Document type: Toolkit Practice area: Corporate — Compliance and Investigations Jurisdiction: United States (federal and Delaware) Last reviewed: 5 September 2026


How to use this toolkit

These are operating documents. Most should be unprivileged business records — deliberately, because their value is as contemporaneous evidence that the program functioned. The investigation materials are different and should be structured for privilege at the outset.

The legal frame is in the companion article: corporate criminal liability attaches readily under New York Central & Hudson River Railroad Co. v. United States, 212 U.S. 481 (1909) and United States v. Hilton Hotels Corp., 467 F.2d 1000 (9th Cir. 1972); the program determines consequence rather than liability; and board-level oversight of mission-critical risks is the standard under Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).


Tool 1: Risk register

The spine of the program. Every other document traces to a row.

# Risk (stated concretely) Business unit / geography Inherent L Inherent I Existing control Control strength Residual Risk owner Control owner Test method Frequency Last tested Result Status
1 Distributor rebate credits in the Gulf approved by a single regional director, paid to unverified accounts, customers include state-owned entities Sales / MEA H H Regional approval only Weak High VP Sales MEA Controller Reperformance + analytics Quarterly
2 Third-party onboarding occurs through three different processes with inconsistent diligence Enterprise H H Fragmented Weak High COO Procurement Dir. Walkthrough + sample Semi-annual
3 Sanctions screening performed at shipping rather than order entry Operations M H Manual, late Moderate High VP Ops Trade Compliance Reperformance Quarterly
4 Hospitality spend per customer not aggregated or monitored Sales / APAC M M Policy limits only Weak Medium VP Sales APAC Compliance Analytics Quarterly

Rules for using it. State risks concretely enough that the control is obvious. Score with documented reasoning. Mark mission-critical risks with a flag of their own, because those are the ones the board must monitor specifically. Refresh annually and on trigger events. If a program activity does not trace to a row, ask why it exists.



Tool 2: Control design worksheet

Complete one per significant risk. The purpose is to force the distinction between a rule and a control.

Risk (register #): ______ What must not happen: ______

Preventive control. What makes the wrong outcome impossible or difficult? ☐ System configuration (specify): ______ ☐ Approval requirement (who, threshold, sequence): ______ ☐ Segregation of duties (which roles must differ): ______ ☐ Access restriction: ______

Detective control. What makes the wrong outcome visible? ☐ Analytic (specify query and threshold): ______ ☐ Reconciliation: ______ ☐ Review (who, what population, what frequency): ______

Bypass analysis. How could someone route around the preventive control? ☐ Manual journal entry ☐ Emergency vendor creation ☐ Alternative payment method ☐ Different business unit ☐ Different system ☐ Other: ______ Each identified bypass must be closed or separately controlled.

Owner (in the business): ______ Test method: ______ Frequency: ______ Policy reference (if any): ______

Effectiveness question: If this control were operating perfectly, would it have prevented or detected the risk event? If the honest answer is "probably not," the control is not adequate.


Tool 3: Testing plan

Control ref. Control description Method Population Sample basis Sample size Tester Period Findings Remediation owner Due Retested Retest result
C-01 Central approval of rebates > $50k Reperformance All rebates > $50k Judgmental — top 3 territories by ratio 40 Internal audit Q2
C-02 Vendor payment blocked absent onboarding Analytics + walkthrough All payments Full population scan n/a Compliance Q2
C-03 Sanctions screening at order entry Reperformance All orders incl. drop-ship Random + all drop-ship 60 Trade compliance Q3
C-04 Hospitality pre-approval and register Sample + analytics All T&E > $500 Judgmental — APAC 50 Internal audit Q3

Rules. Document the sampling basis — judgmental sampling aimed at high-risk populations is often better than random, provided you say what you did and why. Every finding gets a retest, and the retest result is recorded in the same row. Repeat findings escalate to the board.


Tool 4: Analytics library

Ranked by yield. Each entry needs a disposition workflow before it is switched on.

# Analytic Query logic Typical yield Disposition owner
A-1 Threshold-hugging Transactions in the top [5]% band below any approval threshold, by approver and requester Highest Compliance
A-2 Vendor–employee overlap Vendor master bank account, address, phone, or tax ID matching employee master High HR + Compliance
A-3 Third-country payment routing Payment country ≠ vendor country ≠ service country High Compliance
A-4 New vendor, fast payment Vendor created and paid within [30] days, amount > $[__] High Procurement
A-5 No-PO vendors Vendors paid with no purchase order history Medium-high Procurement
A-6 Round-number payments Payments at exact round amounts > $[__], services categories Medium Compliance
A-7 Duplicate invoices Same vendor + amount within [10] days; or same invoice number, different amount Medium AP
A-8 Rebate/discount outliers Rebate-to-revenue ratio by customer, salesperson, territory; flag top decile High Finance
A-9 Hospitality aggregation Sum of T&E by external recipient over rolling [12] months vs. threshold Medium Compliance
A-10 Manual journal entries Manual entries at period end, by unusual users, to unusual accounts, round amounts High Controller
A-11 Bank detail changes Vendor bank changes followed by payment within [15] days High AP
A-12 Sales concentration Revenue by salesperson–customer pair; flag pairs > [__]% of territory Medium Sales ops
A-13 Weekend/holiday expenses Expenses submitted or incurred on non-business days by jurisdiction Low-medium Compliance
A-14 Sequential receipts Sequential receipt numbers across separate claims Low-medium Compliance

Two operating rules. An alert nobody investigates is worse than no alert, because it establishes knowledge. And tuning decisions must be documented — a threshold set to produce a comfortable alert volume is a decision someone will ask about.


Tool 5: Report intake and triage

Intake form.

Report number: ______ Date/time received: ______ Channel: ☐ Hotline ☐ Web ☐ Email ☐ In person ☐ Manager ☐ Board channel Anonymous: ☐ Yes ☐ No · Two-way follow-up available: ☐ Yes ☐ No Reporter (if known): ______ Business unit / location: ______ Allegation as stated by the reporter (verbatim where possible): ______ Individuals named: ______ Seniority of highest individual named: ______ Time period alleged: ______ Amounts alleged: ______ Documents or systems referenced: ______ Reporter's prior reports: ☐ None ☐ [refs] Acknowledgment sent (target: 2 business days): ______

Triage matrix.

Category Route to Escalate to GC Escalate to audit committee Outside counsel Preservation
Financial reporting / accounting Internal audit + Compliance Yes Immediately Usually Immediate
Bribery / corruption Compliance + outside counsel Yes Immediately Yes Immediate
Sanctions / export Trade compliance + Legal Yes If material Usually Immediate
Senior management conduct Outside counsel, independent of management Notify only Immediately Yes Immediate
Retaliation Compliance (not the accused's chain) Yes If substantiated If senior Immediate
Harassment / discrimination HR + Legal If pattern or senior If pattern or senior If senior Yes
Safety / environmental EHS + Legal If material If mission-critical If material Yes
Policy violation, non-legal Manager + HR No No No As needed

Response commitments to publish and measure: acknowledge within 2 business days · triage within 5 · preliminary assessment within 15 · closure communication to the reporter where possible.


Tool 6: Preservation notice

LEGAL HOLD NOTICE — [Matter] — ACTION REQUIRED

You are directed to preserve all documents and communications relating to [subject], for the period [dates], including materials relating to [entities, individuals, transactions].

This obligation covers, without limitation:

  • Email, calendar entries, and attachments, on company and personal accounts used for business
  • Files on company systems, shared drives, cloud storage, and local devices
  • Chat and messaging applications, including [Teams/Slack] and any messaging application used for business communications, on company or personal devices — including applications with automatic deletion features
  • Text messages and voicemail
  • Structured data: ERP records, payment records, expense reports, CRM entries
  • Notes, calendars, and handwritten materials
  • Photographs and recordings

You must immediately: disable any automatic deletion, retention, or "disappearing message" setting on any application you use for business communications; refrain from deleting, editing, or moving any covered material; and preserve devices in their current state.

Do not discuss this notice or its subject matter with anyone other than [contact] and counsel.

Acknowledge receipt by [date] at [link].

And the step that is actually decisive: a technical verification by IT that auto-deletion has been suspended for each custodian, on each platform, with a record of the confirmation. A notice sent is not preservation achieved, and ephemeral messaging is the most common cooperation failure in current practice.


Tool 7: Upjohn warning script

Deliver at the start of every interview. Document delivery. Repeat if circumstances change.

"Before we begin, I need to explain some things about this conversation.

I am a lawyer for [Company]. I represent the Company. I do not represent you.

I am conducting this interview to gather facts so that I can give legal advice to the Company. This conversation is protected by the Company's attorney-client privilege. That privilege belongs to the Company, not to you. That means the Company can decide, without asking you, to share what you tell me with others, including government authorities.

Please keep this conversation confidential and do not discuss it with others, so that the privilege is preserved.

The Company expects you to be truthful and complete. [If applicable: You may wish to consult your own lawyer, and you are free to do so.]

Do you understand what I have explained? Do you have any questions before we begin?"

Record: date, time, attendees, that the warning was given, and that the witness confirmed understanding. Do not paraphrase the warning into something friendlier; the whole value of it is in the clarity.


Tool 8: Root cause analysis form

The document that separates a real remediation from a personnel action.

Matter: ______ Date: ______ Prepared by: ______

1. What happened. Facts, dates, amounts, individuals, duration. ______

2. How was it detected? ☐ Analytic ☐ Testing ☐ Internal report ☐ External report ☐ Audit ☐ Regulator ☐ Media ☐ Counterparty 2a. How long did it run before detection? ______ Why not sooner? ______

3. Which control should have prevented it? ______ 3a. Did that control exist? ☐ Yes ☐ No → design gap 3b. If it existed, did it operate? ☐ Yes ☐ No → operation failure 3c. If it operated, was it bypassed? How? → design gap (bypass)

4. Which control should have detected it? Same three questions. ______

5. Incentives. Did any compensation, target, or promotion structure reward the conduct or the pressure that produced it? → incentive misalignment ______

6. Escalation. Did anyone know or suspect? Did they escalate? If not, why not? Was there a defined trigger and recipient? → escalation failure ______

7. Resourcing. Was any function unable to perform because of staffing, budget, or system access? → resourcing gap / data blindness ______

8. Culture. Would an employee in this unit have believed reporting was safe and useful? What does the culture survey say for this segment? → cultural factor ______

9. Root causes identified (categorized): ______

10. Remediation mapped to each cause (owner, action, date, test): ______

11. Feedback loop. Risk register updated ☐ · Control matrix updated ☐ · Testing plan updated ☐ · Training updated ☐ · Policy updated ☐

The test of a completed form: does any root cause identify a system rather than a person? If every answer is "an employee violated policy," the analysis has not been done.


Tool 9: Remediation tracker

# Matter Root cause category Action Owner Committed date Completed date Test method Retest date Retest result Board reported
R-1 Gulf rebates Control design gap Central approval > $50k Controller Reperformance, n=40
R-2 Gulf rebates Data blindness Compliance ERP read access CIO Access verification
R-3 Gulf rebates Incentive misalignment Compliance modifier in sales incentive plan CHRO Plan document review
R-4 Gulf rebates Control design gap Consolidated third-party onboarding; payment block Procurement Dir. Full-population analytic
R-5 Gulf rebates Escalation failure Defined escalation trigger and recipient for ratio anomalies Compliance Tabletop test

The three columns that matter most are the last three. Remediation without a documented retest is a commitment, not a fix — and at resolution the difference is worth a great deal.


Tool 10: Discipline log

Maintained to demonstrate consistency, which is what regulators and employees both read.

# Matter Individual role / level Conduct Finding Discipline imposed Compensation action Decision-maker Reasoning documented Comparable prior matters
D-1 Gulf rebates Regional Sales Director Directed improper payments Substantiated Termination Unvested equity forfeited CEO + CHRO Yes
D-2 Gulf rebates VP Asia-Pacific Failed to escalate two prior anomalies Substantiated Termination Unvested equity forfeited; bonus clawback CEO + Board Yes
D-3 Gulf rebates Finance Manager Processed without inquiry Substantiated Written warning; training None CFO Yes

Record the decisions not to discipline too, with reasoning. The pattern across the whole log — particularly whether discipline reaches upward — is what is being evaluated, and a log that stops at the executor is a well-documented indictment.


Tool 11: Board reporting package

Standing quarterly contents.

Section Contents
1. Risk register changes New, retired, and re-scored risks, with reasons
2. Mission-critical risk dashboard Status of controls and tests for flagged risks specifically
3. Testing Controls tested this period; exception rate; findings; remediation status; retest results; repeat findings
4. Reporting channel Volume by category; trend; median acknowledgment and closure times; substantiation rate; anonymous share
5. Investigations Matters open and closed; materiality; escalations
6. Discipline By seniority level; compensation actions taken
7. Root cause and program change Analyses completed; changes made as a result
8. Third parties Diligence coverage by risk tier; red flags resolved; terminations
9. Culture Survey results by segment; trend
10. Resourcing Headcount, budget, system access, open positions
11. Regulatory Inquiries, examinations, disclosures

Two numbers the committee should ask about every time: the exception rate in testing (not the number of controls tested), and the trend in report volume (a decline is usually bad news).


Tool 12: Committee charter extract

Compliance Oversight. The Committee shall oversee the Company's compliance program and, specifically, the Company's mission-critical compliance risks, which the Board has identified as: [anti-corruption in the Company's distributor channels]; [export controls and sanctions]; [product safety]; [data protection]. The Committee shall:

(a) review the annual compliance risk assessment and the resulting risk register; (b) receive quarterly reporting on the identified mission-critical risks specifically, including the status of controls and the results of testing; (c) review the results of compliance testing, including exception rates, findings, remediation, and retesting; (d) review reporting channel metrics, including volume, trend, cycle times, and substantiation rates; (e) review discipline imposed by level of seniority and compensation consequences applied; (f) review root cause analyses of material matters and the resulting program changes; (g) meet with the chief compliance officer without management present at least annually; (h) approve the compliance function's budget and staffing recommendation; and (i) receive immediate notification of matters meeting the escalation criteria in the Company's escalation protocol.

Naming the risks specifically is the point. A charter that says "oversee compliance" is the charter Marchand found wanting.


Tool 13: Culture survey questions

Anonymous; annual; reported by segment, never only as an average.

  1. If I observed misconduct, I would report it. (1–5)
  2. If I reported misconduct, I believe the company would act on it. (1–5)
  3. I know how to report a concern. (1–5)
  4. I would not fear retaliation for reporting. (1–5)
  5. In the past year, I have felt pressure to compromise standards to meet a target. (Y/N)
  6. My manager has told me not to worry about a policy or rule. (Y/N)
  7. People at senior levels are held to the same standards as everyone else. (1–5)
  8. Compliance is a real consideration in business decisions here, not a formality. (1–5)
  9. Free text: what is the thing we do that would look worst on the front page?

Read questions 5, 6, and 7 first, by segment. They are the leading indicators. Question 9 is where the next risk assessment comes from.

Interventions that actually move these numbers, in order: visible discipline of a senior person; a compliance decision that visibly cost revenue; leadership discussing a specific incident rather than values; and a fast, respectful response to a report.


Tool 14: Self-disclosure decision memorandum outline

Prepare early; the option can disappear.

1. Facts established to date. What is known, with confidence levels, and what remains unknown. 2. Legal exposure. Statutes implicated — including any accounting exposure under 15 U.S.C. § 78m independent of the underlying conduct. Elements and proof. 3. Seniority. Highest level of involvement or awareness, and the effect on the Guidelines' presumption regarding program effectiveness. 4. Government awareness. Any indication the government knows. Any parallel proceeding, subpoena, or inquiry. 5. Whistleblower risk. Known reporters; exposure under 15 U.S.C. § 78u-6 and, for government revenue, 31 U.S.C. § 3729; the possibility that disclosure ceases to be voluntary at any moment. 6. Disclosure benefit. Availability of the declination presumption; the delta between declination and a deferred prosecution agreement, in dollars and in monitorship exposure. 7. Disclosure cost. Penalty and disgorgement exposure; collateral consequences including debarment, exclusion, and licensing; follow-on civil litigation; and the cost of cooperation itself. 8. Remediation status. What is complete, what is tested, and what can be completed before resolution — the monitor-avoidance posture. 9. Recommendation and the decision-maker. Who decides, and when. 10. If disclosing: timing, channel, scope, preservation confirmation, and the cooperation plan including individual identification and the privilege positions to be taken.


Related documents


This toolkit is general information, not legal advice, and does not create an attorney-client relationship. Adapt every document to the organization.