Document type: Toolkit Practice area: Corporate — Compliance and Investigations Jurisdiction: United States (federal and Delaware) Last reviewed: 5 September 2026
How to use this toolkit
These are operating documents. Most should be unprivileged business records — deliberately, because their value is as contemporaneous evidence that the program functioned. The investigation materials are different and should be structured for privilege at the outset.
The legal frame is in the companion article: corporate criminal liability attaches readily under New York Central & Hudson River Railroad Co. v. United States, 212 U.S. 481 (1909) and United States v. Hilton Hotels Corp., 467 F.2d 1000 (9th Cir. 1972); the program determines consequence rather than liability; and board-level oversight of mission-critical risks is the standard under Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).
Tool 1: Risk register
The spine of the program. Every other document traces to a row.
| # | Risk (stated concretely) | Business unit / geography | Inherent L | Inherent I | Existing control | Control strength | Residual | Risk owner | Control owner | Test method | Frequency | Last tested | Result | Status |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Distributor rebate credits in the Gulf approved by a single regional director, paid to unverified accounts, customers include state-owned entities | Sales / MEA | H | H | Regional approval only | Weak | High | VP Sales MEA | Controller | Reperformance + analytics | Quarterly | |||
| 2 | Third-party onboarding occurs through three different processes with inconsistent diligence | Enterprise | H | H | Fragmented | Weak | High | COO | Procurement Dir. | Walkthrough + sample | Semi-annual | |||
| 3 | Sanctions screening performed at shipping rather than order entry | Operations | M | H | Manual, late | Moderate | High | VP Ops | Trade Compliance | Reperformance | Quarterly | |||
| 4 | Hospitality spend per customer not aggregated or monitored | Sales / APAC | M | M | Policy limits only | Weak | Medium | VP Sales APAC | Compliance | Analytics | Quarterly |
Rules for using it. State risks concretely enough that the control is obvious. Score with documented reasoning. Mark mission-critical risks with a flag of their own, because those are the ones the board must monitor specifically. Refresh annually and on trigger events. If a program activity does not trace to a row, ask why it exists.
Tool 2: Control design worksheet
Complete one per significant risk. The purpose is to force the distinction between a rule and a control.
Risk (register #): ______ What must not happen: ______
Preventive control. What makes the wrong outcome impossible or difficult? ☐ System configuration (specify): ______ ☐ Approval requirement (who, threshold, sequence): ______ ☐ Segregation of duties (which roles must differ): ______ ☐ Access restriction: ______
Detective control. What makes the wrong outcome visible? ☐ Analytic (specify query and threshold): ______ ☐ Reconciliation: ______ ☐ Review (who, what population, what frequency): ______
Bypass analysis. How could someone route around the preventive control? ☐ Manual journal entry ☐ Emergency vendor creation ☐ Alternative payment method ☐ Different business unit ☐ Different system ☐ Other: ______ Each identified bypass must be closed or separately controlled.
Owner (in the business): ______ Test method: ______ Frequency: ______ Policy reference (if any): ______
Effectiveness question: If this control were operating perfectly, would it have prevented or detected the risk event? If the honest answer is "probably not," the control is not adequate.
Tool 3: Testing plan
| Control ref. | Control description | Method | Population | Sample basis | Sample size | Tester | Period | Findings | Remediation owner | Due | Retested | Retest result |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| C-01 | Central approval of rebates > $50k | Reperformance | All rebates > $50k | Judgmental — top 3 territories by ratio | 40 | Internal audit | Q2 | |||||
| C-02 | Vendor payment blocked absent onboarding | Analytics + walkthrough | All payments | Full population scan | n/a | Compliance | Q2 | |||||
| C-03 | Sanctions screening at order entry | Reperformance | All orders incl. drop-ship | Random + all drop-ship | 60 | Trade compliance | Q3 | |||||
| C-04 | Hospitality pre-approval and register | Sample + analytics | All T&E > $500 | Judgmental — APAC | 50 | Internal audit | Q3 |
Rules. Document the sampling basis — judgmental sampling aimed at high-risk populations is often better than random, provided you say what you did and why. Every finding gets a retest, and the retest result is recorded in the same row. Repeat findings escalate to the board.
Tool 4: Analytics library
Ranked by yield. Each entry needs a disposition workflow before it is switched on.
| # | Analytic | Query logic | Typical yield | Disposition owner |
|---|---|---|---|---|
| A-1 | Threshold-hugging | Transactions in the top [5]% band below any approval threshold, by approver and requester | Highest | Compliance |
| A-2 | Vendor–employee overlap | Vendor master bank account, address, phone, or tax ID matching employee master | High | HR + Compliance |
| A-3 | Third-country payment routing | Payment country ≠ vendor country ≠ service country | High | Compliance |
| A-4 | New vendor, fast payment | Vendor created and paid within [30] days, amount > $[__] | High | Procurement |
| A-5 | No-PO vendors | Vendors paid with no purchase order history | Medium-high | Procurement |
| A-6 | Round-number payments | Payments at exact round amounts > $[__], services categories | Medium | Compliance |
| A-7 | Duplicate invoices | Same vendor + amount within [10] days; or same invoice number, different amount | Medium | AP |
| A-8 | Rebate/discount outliers | Rebate-to-revenue ratio by customer, salesperson, territory; flag top decile | High | Finance |
| A-9 | Hospitality aggregation | Sum of T&E by external recipient over rolling [12] months vs. threshold | Medium | Compliance |
| A-10 | Manual journal entries | Manual entries at period end, by unusual users, to unusual accounts, round amounts | High | Controller |
| A-11 | Bank detail changes | Vendor bank changes followed by payment within [15] days | High | AP |
| A-12 | Sales concentration | Revenue by salesperson–customer pair; flag pairs > [__]% of territory | Medium | Sales ops |
| A-13 | Weekend/holiday expenses | Expenses submitted or incurred on non-business days by jurisdiction | Low-medium | Compliance |
| A-14 | Sequential receipts | Sequential receipt numbers across separate claims | Low-medium | Compliance |
Two operating rules. An alert nobody investigates is worse than no alert, because it establishes knowledge. And tuning decisions must be documented — a threshold set to produce a comfortable alert volume is a decision someone will ask about.
Tool 5: Report intake and triage
Intake form.
Report number: ______ Date/time received: ______ Channel: ☐ Hotline ☐ Web ☐ Email ☐ In person ☐ Manager ☐ Board channel Anonymous: ☐ Yes ☐ No · Two-way follow-up available: ☐ Yes ☐ No Reporter (if known): ______ Business unit / location: ______ Allegation as stated by the reporter (verbatim where possible): ______ Individuals named: ______ Seniority of highest individual named: ______ Time period alleged: ______ Amounts alleged: ______ Documents or systems referenced: ______ Reporter's prior reports: ☐ None ☐ [refs] Acknowledgment sent (target: 2 business days): ______
Triage matrix.
| Category | Route to | Escalate to GC | Escalate to audit committee | Outside counsel | Preservation |
|---|---|---|---|---|---|
| Financial reporting / accounting | Internal audit + Compliance | Yes | Immediately | Usually | Immediate |
| Bribery / corruption | Compliance + outside counsel | Yes | Immediately | Yes | Immediate |
| Sanctions / export | Trade compliance + Legal | Yes | If material | Usually | Immediate |
| Senior management conduct | Outside counsel, independent of management | Notify only | Immediately | Yes | Immediate |
| Retaliation | Compliance (not the accused's chain) | Yes | If substantiated | If senior | Immediate |
| Harassment / discrimination | HR + Legal | If pattern or senior | If pattern or senior | If senior | Yes |
| Safety / environmental | EHS + Legal | If material | If mission-critical | If material | Yes |
| Policy violation, non-legal | Manager + HR | No | No | No | As needed |
Response commitments to publish and measure: acknowledge within 2 business days · triage within 5 · preliminary assessment within 15 · closure communication to the reporter where possible.
Tool 6: Preservation notice
LEGAL HOLD NOTICE — [Matter] — ACTION REQUIRED
You are directed to preserve all documents and communications relating to [subject], for the period [dates], including materials relating to [entities, individuals, transactions].
This obligation covers, without limitation:
- Email, calendar entries, and attachments, on company and personal accounts used for business
- Files on company systems, shared drives, cloud storage, and local devices
- Chat and messaging applications, including [Teams/Slack] and any messaging application used for business communications, on company or personal devices — including applications with automatic deletion features
- Text messages and voicemail
- Structured data: ERP records, payment records, expense reports, CRM entries
- Notes, calendars, and handwritten materials
- Photographs and recordings
You must immediately: disable any automatic deletion, retention, or "disappearing message" setting on any application you use for business communications; refrain from deleting, editing, or moving any covered material; and preserve devices in their current state.
Do not discuss this notice or its subject matter with anyone other than [contact] and counsel.
Acknowledge receipt by [date] at [link].
And the step that is actually decisive: a technical verification by IT that auto-deletion has been suspended for each custodian, on each platform, with a record of the confirmation. A notice sent is not preservation achieved, and ephemeral messaging is the most common cooperation failure in current practice.
Tool 7: Upjohn warning script
Deliver at the start of every interview. Document delivery. Repeat if circumstances change.
"Before we begin, I need to explain some things about this conversation.
I am a lawyer for [Company]. I represent the Company. I do not represent you.
I am conducting this interview to gather facts so that I can give legal advice to the Company. This conversation is protected by the Company's attorney-client privilege. That privilege belongs to the Company, not to you. That means the Company can decide, without asking you, to share what you tell me with others, including government authorities.
Please keep this conversation confidential and do not discuss it with others, so that the privilege is preserved.
The Company expects you to be truthful and complete. [If applicable: You may wish to consult your own lawyer, and you are free to do so.]
Do you understand what I have explained? Do you have any questions before we begin?"
Record: date, time, attendees, that the warning was given, and that the witness confirmed understanding. Do not paraphrase the warning into something friendlier; the whole value of it is in the clarity.
Tool 8: Root cause analysis form
The document that separates a real remediation from a personnel action.
Matter: ______ Date: ______ Prepared by: ______
1. What happened. Facts, dates, amounts, individuals, duration. ______
2. How was it detected? ☐ Analytic ☐ Testing ☐ Internal report ☐ External report ☐ Audit ☐ Regulator ☐ Media ☐ Counterparty 2a. How long did it run before detection? ______ Why not sooner? ______
3. Which control should have prevented it? ______ 3a. Did that control exist? ☐ Yes ☐ No → design gap 3b. If it existed, did it operate? ☐ Yes ☐ No → operation failure 3c. If it operated, was it bypassed? How? → design gap (bypass)
4. Which control should have detected it? Same three questions. ______
5. Incentives. Did any compensation, target, or promotion structure reward the conduct or the pressure that produced it? → incentive misalignment ______
6. Escalation. Did anyone know or suspect? Did they escalate? If not, why not? Was there a defined trigger and recipient? → escalation failure ______
7. Resourcing. Was any function unable to perform because of staffing, budget, or system access? → resourcing gap / data blindness ______
8. Culture. Would an employee in this unit have believed reporting was safe and useful? What does the culture survey say for this segment? → cultural factor ______
9. Root causes identified (categorized): ______
10. Remediation mapped to each cause (owner, action, date, test): ______
11. Feedback loop. Risk register updated ☐ · Control matrix updated ☐ · Testing plan updated ☐ · Training updated ☐ · Policy updated ☐
The test of a completed form: does any root cause identify a system rather than a person? If every answer is "an employee violated policy," the analysis has not been done.
Tool 9: Remediation tracker
| # | Matter | Root cause category | Action | Owner | Committed date | Completed date | Test method | Retest date | Retest result | Board reported |
|---|---|---|---|---|---|---|---|---|---|---|
| R-1 | Gulf rebates | Control design gap | Central approval > $50k | Controller | Reperformance, n=40 | |||||
| R-2 | Gulf rebates | Data blindness | Compliance ERP read access | CIO | Access verification | |||||
| R-3 | Gulf rebates | Incentive misalignment | Compliance modifier in sales incentive plan | CHRO | Plan document review | |||||
| R-4 | Gulf rebates | Control design gap | Consolidated third-party onboarding; payment block | Procurement Dir. | Full-population analytic | |||||
| R-5 | Gulf rebates | Escalation failure | Defined escalation trigger and recipient for ratio anomalies | Compliance | Tabletop test |
The three columns that matter most are the last three. Remediation without a documented retest is a commitment, not a fix — and at resolution the difference is worth a great deal.
Tool 10: Discipline log
Maintained to demonstrate consistency, which is what regulators and employees both read.
| # | Matter | Individual role / level | Conduct | Finding | Discipline imposed | Compensation action | Decision-maker | Reasoning documented | Comparable prior matters |
|---|---|---|---|---|---|---|---|---|---|
| D-1 | Gulf rebates | Regional Sales Director | Directed improper payments | Substantiated | Termination | Unvested equity forfeited | CEO + CHRO | Yes | |
| D-2 | Gulf rebates | VP Asia-Pacific | Failed to escalate two prior anomalies | Substantiated | Termination | Unvested equity forfeited; bonus clawback | CEO + Board | Yes | |
| D-3 | Gulf rebates | Finance Manager | Processed without inquiry | Substantiated | Written warning; training | None | CFO | Yes |
Record the decisions not to discipline too, with reasoning. The pattern across the whole log — particularly whether discipline reaches upward — is what is being evaluated, and a log that stops at the executor is a well-documented indictment.
Tool 11: Board reporting package
Standing quarterly contents.
| Section | Contents |
|---|---|
| 1. Risk register changes | New, retired, and re-scored risks, with reasons |
| 2. Mission-critical risk dashboard | Status of controls and tests for flagged risks specifically |
| 3. Testing | Controls tested this period; exception rate; findings; remediation status; retest results; repeat findings |
| 4. Reporting channel | Volume by category; trend; median acknowledgment and closure times; substantiation rate; anonymous share |
| 5. Investigations | Matters open and closed; materiality; escalations |
| 6. Discipline | By seniority level; compensation actions taken |
| 7. Root cause and program change | Analyses completed; changes made as a result |
| 8. Third parties | Diligence coverage by risk tier; red flags resolved; terminations |
| 9. Culture | Survey results by segment; trend |
| 10. Resourcing | Headcount, budget, system access, open positions |
| 11. Regulatory | Inquiries, examinations, disclosures |
Two numbers the committee should ask about every time: the exception rate in testing (not the number of controls tested), and the trend in report volume (a decline is usually bad news).
Tool 12: Committee charter extract
Compliance Oversight. The Committee shall oversee the Company's compliance program and, specifically, the Company's mission-critical compliance risks, which the Board has identified as: [anti-corruption in the Company's distributor channels]; [export controls and sanctions]; [product safety]; [data protection]. The Committee shall:
(a) review the annual compliance risk assessment and the resulting risk register; (b) receive quarterly reporting on the identified mission-critical risks specifically, including the status of controls and the results of testing; (c) review the results of compliance testing, including exception rates, findings, remediation, and retesting; (d) review reporting channel metrics, including volume, trend, cycle times, and substantiation rates; (e) review discipline imposed by level of seniority and compensation consequences applied; (f) review root cause analyses of material matters and the resulting program changes; (g) meet with the chief compliance officer without management present at least annually; (h) approve the compliance function's budget and staffing recommendation; and (i) receive immediate notification of matters meeting the escalation criteria in the Company's escalation protocol.
Naming the risks specifically is the point. A charter that says "oversee compliance" is the charter Marchand found wanting.
Tool 13: Culture survey questions
Anonymous; annual; reported by segment, never only as an average.
- If I observed misconduct, I would report it. (1–5)
- If I reported misconduct, I believe the company would act on it. (1–5)
- I know how to report a concern. (1–5)
- I would not fear retaliation for reporting. (1–5)
- In the past year, I have felt pressure to compromise standards to meet a target. (Y/N)
- My manager has told me not to worry about a policy or rule. (Y/N)
- People at senior levels are held to the same standards as everyone else. (1–5)
- Compliance is a real consideration in business decisions here, not a formality. (1–5)
- Free text: what is the thing we do that would look worst on the front page?
Read questions 5, 6, and 7 first, by segment. They are the leading indicators. Question 9 is where the next risk assessment comes from.
Interventions that actually move these numbers, in order: visible discipline of a senior person; a compliance decision that visibly cost revenue; leadership discussing a specific incident rather than values; and a fast, respectful response to a report.
Tool 14: Self-disclosure decision memorandum outline
Prepare early; the option can disappear.
1. Facts established to date. What is known, with confidence levels, and what remains unknown. 2. Legal exposure. Statutes implicated — including any accounting exposure under 15 U.S.C. § 78m independent of the underlying conduct. Elements and proof. 3. Seniority. Highest level of involvement or awareness, and the effect on the Guidelines' presumption regarding program effectiveness. 4. Government awareness. Any indication the government knows. Any parallel proceeding, subpoena, or inquiry. 5. Whistleblower risk. Known reporters; exposure under 15 U.S.C. § 78u-6 and, for government revenue, 31 U.S.C. § 3729; the possibility that disclosure ceases to be voluntary at any moment. 6. Disclosure benefit. Availability of the declination presumption; the delta between declination and a deferred prosecution agreement, in dollars and in monitorship exposure. 7. Disclosure cost. Penalty and disgorgement exposure; collateral consequences including debarment, exclusion, and licensing; follow-on civil litigation; and the cost of cooperation itself. 8. Remediation status. What is complete, what is tested, and what can be completed before resolution — the monitor-avoidance posture. 9. Recommendation and the decision-maker. Who decides, and when. 10. If disclosing: timing, channel, scope, preservation confirmation, and the cooperation plan including individual identification and the privilege positions to be taken.
Related documents
- Corporate Compliance Programs: The ECCP, Monitorships, and What Regulators Actually Credit
- Designing and Testing a Compliance Program: A Practical Guide
- Compliance Program Effectiveness Checklist: A Practical Checklist
- Conducting an Internal Investigation: Scope, Privilege, and Reporting
- Internal Investigation and Upjohn Warning Checklist: A Practical Checklist
- White Collar Criminal Investigations: Grand Jury Subpoenas, Internal Investigations, and Corporate Cooperation
This toolkit is general information, not legal advice, and does not create an attorney-client relationship. Adapt every document to the organization.