Document type: Guide Practice area: Corporate — Compliance and Investigations Jurisdiction: United States (federal and Delaware) Last reviewed: 5 September 2026
Before anything: understand what you are building for
A compliance program is evaluated by three audiences with different questions, and a program built for only one of them fails the others.
A prosecutor asks whether the program was well designed, adequately resourced and empowered, and working in practice — and asks it twice: as of the conduct, and as of the charging decision.
A court in a derivative action asks whether the board made a good-faith effort to assure that a reporting system exists for the company's mission-critical risks, under In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996) as confirmed in Stone v. Ritter, 911 A.2d 362 (Del. 2006) and applied in Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).
The workforce asks whether reporting a problem is safe and whether anything happens when they do. This is the audience that determines whether the program detects anything at all, and it is the one most often ignored in design.
Build for all three. They want mostly the same things.
Step 1: The risk assessment
Everything traces to this. A program that cannot be traced to a risk assessment cannot answer the first question a prosecutor asks.
1.1 Define the universe. Walk the business, not the org chart. Where does revenue come from? Through what channels? In what countries? Who are the customers — commercial, government, state-owned? Who are the intermediaries? What is bought, from whom, and how is it paid for? What is regulated?
1.2 Enumerate the risks concretely. Not "bribery risk" but "our Gulf distributors receive rebate credits approved only by the regional sales director, and one of our largest customers is state-owned." A risk stated abstractly cannot be controlled; a risk stated concretely names its own control.
1.3 Score. Inherent likelihood and impact, then existing control strength, then residual risk. Use a consistent scale and document the reasoning for each score — the reasoning is what makes the assessment defensible, not the number.
1.4 Interview widely. Sales, procurement, finance, operations, legal, internal audit, and — importantly — people two levels below the executives. The most useful sentence in a risk assessment interview is "what do we do that would look bad if it were on the front page?" and junior people answer it more honestly.
1.5 Use the data. Payment records to unusual jurisdictions. Vendors with no procurement history. Expense patterns. Discount and rebate outliers. Customers concentrated with one salesperson. Data finds risks that interviews miss.
1.6 Produce a risk register, and make it the spine of the program: each risk, its score, its owner, the control that addresses it, the test that verifies the control, the last test date, and the result.
1.7 Refresh annually and on trigger events — an acquisition, entry into a new market, a new product line, a regulatory change, or an incident.
A note on scope. Assess the risk of legal violation, not business risk generally. And assess mission-critical risks explicitly and separately, because Marchand makes board-level monitoring of those specifically the standard.
Step 2: Convert risks into controls
The distinction that matters. A policy says what people should do. A control makes the wrong outcome hard or detectable. Regulators credit controls.
| Risk | Policy (weak alone) | Control (what to build) |
|---|---|---|
| Improper payments to intermediaries | "Employees may not make improper payments" | Vendor onboarding blocked without completed diligence; payments to unapproved vendors rejected by the system; second approval above a threshold |
| Rebate abuse | "Rebates must be justified" | Central approval above a threshold; automated rebate-to-revenue ratio analytics with escalation |
| Expense fraud | "Expenses must be business-related" | Receipt requirement with automated matching; approval by someone other than the beneficiary; analytics on round numbers and threshold-hugging |
| Conflicts of interest | Annual disclosure form | Disclosure at transaction level; vendor master screened against employee address and bank data |
| Gifts and hospitality | Value limits in a policy | Pre-approval workflow with a register; automated flag on aggregated recipient totals |
| Trade and sanctions | "Comply with export laws" | Screening embedded in order entry; blocked-party hits routed to compliance before shipment |
| Books and records | "Records must be accurate" | Account use restrictions; journal entry approval; period-end review of manual entries |
Assign an owner to every control — a named person, in the business, accountable for its operation. Compliance owns the program; the business owns the controls.
Write the policies anyway, but keep them short, in the right languages, and located where the decision is made. A three-hundred-page code nobody reads is a liability; a one-page procurement standard embedded in the purchase order workflow is a control.
Step 3: Build the reporting channel
It has to compete. 15 U.S.C. § 78u-6 pays securities whistleblowers between ten and thirty percent of sanctions above a threshold, and Digital Realty Trust, Inc. v. Somers, 583 U.S. 149 (2018) held that Dodd-Frank's anti-retaliation protection reaches only those who report to the Commission — which pushes reporters outward. For companies with government revenue, 31 U.S.C. § 3729 qui tam actions do the same. Your internal channel competes on speed, credibility, and safety.
Design specifications.
- Multiple intake paths. Hotline, web form, email, direct to compliance, direct to any manager, and direct to the board's designated channel.
- Anonymity where lawfully available, with a mechanism for two-way anonymous follow-up — reports that cannot be clarified usually cannot be substantiated.
- A case management system. Every report logged with a unique number, category, intake date, assignment, status, findings, and closure. A hotline without a case management system is a voicemail box.
- Response commitments. Acknowledge within two business days. Triage within five. Preliminary assessment within fifteen. Publish these and meet them.
- Triage criteria. What goes to compliance, HR, internal audit, or outside counsel; what escalates to the general counsel; what escalates to the audit committee immediately.
- Consistency. Similar allegations get similar investigative rigor regardless of who is accused. Inconsistency here is the single most damaging pattern a program can have.
The retaliation control. Every adverse employment action — termination, demotion, material change in duties, negative review, denial of promotion — affecting anyone who has made a report within the preceding twelve to twenty-four months requires compliance review before execution. This one control prevents an entire category of disaster, and it costs almost nothing.
Protect the channel contractually. Separation agreements, confidentiality agreements, and codes of conduct must expressly carve out communications with regulators. Internal reporters retain protection under 18 U.S.C. § 1514A and other statutes; the company should not be seen to impede either route.
Step 4: Training that is not theater
Segment by risk, not by headcount. The sales organization in a high-risk region needs a different session from the finance team in headquarters, which needs a different session from warehouse staff.
Use the company's own facts. Anonymized versions of actual incidents, actual close calls, and actual decisions. A scenario drawn from the company's own history is worth ten generic hypotheticals.
Train managers separately on their obligations: how to receive a report, what to do in the next hour, what not to promise, and the prohibition on retaliation.
Test comprehension, not completion. A short assessment with scenario questions tells you whether the message landed. Completion percentage tells you nothing.
Track and follow up. Non-completion by a high-risk employee is itself a finding.
Refresh on incidents. After a substantiated report, the relevant population gets targeted training on that specific failure — which is also evidence of the Guidelines' seventh element in operation.
Step 5: Third-party diligence
For most companies this is the highest-return control in the program, because most exposure arrives through intermediaries — and under 15 U.S.C. § 78dd-1, payments through third parties are reachable where the company knows or is aware of a high probability of the improper use.
The workflow.
- Trigger. Nothing gets onboarded or paid without passing through it. If the finance system can pay a vendor who never entered the workflow, the workflow does not exist.
- Risk tier. Based on geography, government interaction, function (agents and consultants are higher risk than commodity suppliers), and compensation structure.
- Screening. Sanctions, denied party, politically exposed persons, adverse media, and litigation.
- Questionnaire. Ownership and beneficial ownership; government officials among owners, managers, or family; other clients; compensation basis; and subcontractors.
- Red flag resolution. Every flag documented with the resolution and who approved it. An unresolved flag with an approval is worse than no diligence at all.
- Contract terms. Anti-corruption and sanctions representations, compliance covenants, audit rights, training obligations, termination for breach, and a prohibition on subcontracting without consent.
- Payment controls. No payments to accounts in third countries; no cash; no round-number "success fees" without documentation; invoices describing services actually rendered.
- Refresh. Annually for high-risk, biennially otherwise, and on trigger events.
- Monitoring. Analytics on payment patterns, and periodic audits of the highest-risk relationships.
Make it usable. Diligence workflows that take six weeks get bypassed. Build a fast path for low-risk vendors so the business does not have an incentive to route around the system.
Step 6: Testing and monitoring — the part that distinguishes real programs
Monitoring is continuous and operational. Testing is periodic and independent. You need both.
Design the testing plan from the risk register. Each significant risk maps to a control; each control gets a test with a defined method, frequency, sample size, and owner.
Testing methods.
- Reperformance. Take a sample of transactions and redo the control: did the second approval occur, by an authorized person, before the payment?
- Sampling. Statistical or judgmental, with the basis documented. Judgmental sampling aimed at higher-risk populations is often more useful than a random sample, provided you say what you did.
- Analytics. Payments to high-risk jurisdictions. Vendors sharing bank details with employees. Invoices just under approval thresholds. Round-number payments. Duplicate invoices. Discount outliers by salesperson. Journal entries posted at unusual times. Threshold-hugging is the most reliable single indicator in the set.
- Walkthroughs. Sit with the person operating the control and watch them do it. This finds controls that exist on paper and are worked around in practice.
- Interviews and surveys. Anonymous culture surveys asking whether people would report, whether they believe anything would happen, and whether they have felt pressure to compromise. A declining willingness-to-report score is an early warning worth more than most metrics.
Document findings and remediate them with dates and owners. Then retest. A finding closed without retesting is a finding you have decided to believe.
A testing program that never finds anything is not being run properly. Say this to the audit committee before someone else does.
Who tests. Internal audit, compliance, or outside counsel, depending on sensitivity and privilege posture. Where the test is likely to find legal violations, structure it for privilege deliberately at the outset — and understand that routine operational testing generally is not privileged and probably should not be.
Step 7: Investigate properly
Hour one: preserve. Issue the hold. Cover email, files, chat, messaging applications including personal devices used for business, and structured data. Then verify with IT that auto-deletion has actually stopped. Ephemeral messaging is the most common cooperation failure in modern practice, and the failure is almost always technical rather than intentional.
Day one: scope and structure. What is alleged, who is implicated, what is the potential legal exposure, and how senior are the people involved? Seniority changes everything, including whether the Guidelines' rebuttable presumption against program effectiveness applies. Engage outside counsel where the exposure is material or where independence matters. Decide the privilege structure and document it.
Notify the audit committee chair where the matter is material, and do it early. A committee that learns of a matter from the government has been failed by management.
Investigate. Document review before interviews. Interviews from the outside in. An Upjohn warning at the start of every interview — counsel represents the company, not the individual; the privilege belongs to the company; the company may waive it — delivered, documented, and repeated if circumstances change. Separate counsel for individuals whose conduct is genuinely at issue, with the advancement question resolved on the charter, bylaws, and indemnification agreements rather than ad hoc.
Decide on self-disclosure deliberately and early. The declination framework rewards genuinely voluntary disclosure, full cooperation, and timely remediation. A whistleblower can eliminate the option at any moment, which argues for speed.
Never obstruct, including softly. Selective production, coached witnesses, and delay are all obstruction in substance, and 18 U.S.C. § 1001 reaches false statements made during the investigation itself.
Step 8: Root cause analysis and remediation
The distinction that decides cases. Incident description says an employee violated policy. Root cause analysis asks why the control did not catch it, why the incentive rewarded it, why nobody escalated, and why nobody noticed for three years.
A workable method. For each finding, ask "why" until the answer is a system rather than a person. Then categorize: control design gap; control operation failure; incentive misalignment; escalation failure; resourcing gap; data blindness; or cultural factor.
Then design remediation to the causes, not the symptom:
- Control design gap → build the control, with an owner and a test.
- Operation failure → retrain, re-staff, or automate; then retest.
- Incentive misalignment → change the compensation plan, not the policy.
- Escalation failure → define the trigger and the recipient, and test it.
- Resourcing gap → fund it, and record the funding decision.
- Data blindness → give compliance system access.
- Cultural factor → the hardest, and the one where discipline of senior people does more than any training.
Discipline consistently and upward. Terminating the executor and retaining the supervisor who created the pressure is a pattern regulators recognize immediately. Document the reasoning for every disciplinary decision, including the decisions not to discipline.
Use compensation. Clawbacks and forfeiture of unvested awards, applied where warranted. Compliance modifiers in incentive plans, applied prospectively. This is arithmetic a board understands and a prosecutor credits.
Complete and test remediation before resolution if you possibly can. Remediation completed and tested is the strongest monitor-avoidance argument available; remediation promised in an agreement is not.
Feed everything back into the risk assessment, the control set, the testing plan, and the training. That loop is the Guidelines' seventh element, and it is the one most often missing.
Step 9: Board reporting that proves oversight
Charter it. A committee charter that names the company's mission-critical compliance risks specifically — not "compliance" generically. This is the direct lesson of Marchand, where the absence of any board-level structure for the company's central risk was decisive.
Set a cadence and keep it: quarterly reporting, with an annual deep dive on the risk assessment.
Report the right things. Risk register changes. Testing performed and exception rates. Report volume, cycle times, substantiation rates, and discipline by level of seniority. Root cause analyses and resulting program changes. Repeat findings. Third-party diligence coverage. Resourcing.
Give the compliance officer time alone with the committee, at least annually, without management present.
Write minutes that show engagement. Not "management presented a compliance update." Rather: the committee reviewed the exception rate in the third-party payment testing, asked why two regions accounted for most exceptions, and directed management to report back with a remediation plan by the next meeting. Minutes are the evidence years later, and they are free to write well.
Worked example: building the program at Vantage Precision
Vantage Precision — industrial sensors, one point four billion in revenue, plants in Ohio and Malaysia, distributor sales across Southeast Asia and the Gulf. General counsel Adaeze Fontaine is asked by a new audit committee chair to assess the program. She finds a code of conduct, an annual online training module with a ninety-six percent completion rate, a hotline run by a vendor, and no risk assessment.
Month 1: the risk assessment. Adaeze runs it herself with two outside consultants and thirty-one interviews. The most productive question — "what do we do that would look bad on the front page?" — is asked of everyone below the executive level.
The register that emerges has eleven risks. The top four:
- Distributor rebates in the Gulf and Southeast Asia, approved by a single regional sales director, paid into accounts the company does not verify, sold into state-owned customers.
- Third-party onboarding, which happens three different ways depending on which business unit initiates it, with no consistent diligence.
- Export controls and sanctions screening, performed manually at shipping rather than at order entry.
- Expense and gift practices in Asia-Pacific, where the aggregate hospitality spend per customer is not tracked.
Data confirms three of the four before any interview does. A query of the payment ledger finds forty-one vendors with no purchase orders, eleven payments to jurisdictions where Vantage has no operations, and a rebate-to-revenue ratio in one Gulf territory that is four times the global average.
Month 2: controls, not policies. Each of the eleven risks gets a control, a named business owner, and a test.
- Rebates above fifty thousand dollars now require central finance approval. A monthly analytic flags rebate-to-revenue outliers by distributor.
- All third-party onboarding consolidates into one workflow, and the ERP is configured to reject payment to any vendor not onboarded through it. This is the control that mattered most, and it was a configuration change.
- Screening moves from shipping to order entry, with hits routed to compliance before allocation.
- Gift and hospitality pre-approval with a register, and an aggregation flag per recipient.
Month 3: the reporting channel. The vendor hotline stays; a case management system is added. Response commitments — acknowledge in two days, triage in five, preliminary assessment in fifteen — are published. The retaliation control is instituted: HR cannot execute an adverse action affecting anyone who reported in the preceding twenty-four months without compliance review.
Month 4: compliance gets access. Adaeze wins a fight to give the compliance function direct read access to the ERP payment tables. This single change converts compliance from a function that receives reports into a function that detects.
Months 5–8: testing. Internal audit tests six controls against samples. Findings: the vendor payment block can be bypassed by a manual journal entry (design gap); the gift register is being completed after the fact (operation failure); screening at order entry misses drop-ship orders (design gap). All three are remediated, and all three are retested in month nine.
Month 6: the culture survey. Sixty-one percent of respondents say they would report misconduct; forty-four percent believe something would happen if they did. In Asia-Pacific those numbers are forty-one and twenty-six. Adaeze treats this as the most important finding of the year, and it drives targeted work: regional town halls, a local-language channel, and the visible discipline that comes later.
Month 7: the hotline report described in the companion article arrives. The program is eight months old. Because preservation capability exists, the hold works. Because compliance has ERP access, the payment analysis takes days rather than weeks. Because the risk register had already identified Gulf rebates as risk number one, the board is not surprised and the committee minutes show the risk was flagged and being remediated.
Month 9: discipline. The regional director and his supervisor are terminated. Unvested equity is forfeited. The termination of the vice president is announced internally — not the details, but the fact that a senior person was terminated for a compliance failure. The next culture survey shows willingness-to-report in Asia-Pacific at sixty-three percent.
Month 12: the metrics package to the audit committee shows: eleven risks with owners and tests; six controls tested with three findings, all remediated and retested; report volume up forty percent (a good sign, not a bad one); median time to acknowledgment of one day; discipline imposed at four levels of seniority including a vice president; one root cause analysis completed and four controls changed as a result.
What Adaeze would tell you mattered. The risk assessment, because it made everything else traceable. The ERP payment block, because it was a control rather than a rule. Compliance data access, because detection is the whole game. And terminating the vice president, because it was the only thing that changed what people believed.
Program sizing
A hundred-person company. No dedicated compliance staff. The general counsel or the CFO owns the program. What still has to exist: a one-page risk register, reviewed annually by the board or the owner; a reporting channel with a response commitment and a retaliation control; separation between the person who executes payments and the person who approves them; testing of the top three controls once a year, possibly by an outside accountant; and consistent discipline. This is a few days a quarter, and it is genuinely adequate at that scale.
A thousand-person company. A compliance officer, probably part-time on other duties, with a direct line to the audit committee. A risk register with fifteen to thirty entries. A case management system. A testing plan run with internal audit. Third-party diligence workflow. Targeted training. Quarterly board reporting.
A multinational. Everything above, plus regional compliance staffing, local-language channels, country risk assessments, dedicated analytics, an M&A integration protocol, and a documented program governance structure.
What does not scale down at any size: the risk assessment, board or owner-level oversight of the top risks, a working reporting channel, testing of the most important controls, consistent discipline, and root cause analysis. What does scale down: headcount, formality, documentation volume, and metrics sophistication.
The failure mode at small scale is one person who executes and reviews, with an owner whose word overrides every control. The failure mode at large scale is formal completeness with operational hollowness — every element present, nothing tested, nobody senior ever disciplined.
Compliance in acquisitions
Pre-signing. Risk-based diligence: geography, customer type, sales model, intermediaries, government interaction. Review the target's own risk assessment and testing results if any exist — the absence of both is itself a finding. Ask for hotline reports, terminations for cause, and any investigation files.
In the agreement. Anti-corruption, sanctions, and trade compliance representations. Pre- and post-closing access to records. Indemnity, and consideration of insurance. In a stock deal the exposure comes with the entity; in an asset deal, evaluate successor liability carefully rather than assuming it does not follow.
Post-closing, on a published timeline. Extend policies, the reporting channel, and the third-party workflow. Re-onboard the target's intermediaries through the acquirer's diligence. Train on what is actually different. Test within the timeline, and record that you met it.
If diligence or integration finds misconduct. Investigate promptly, remediate, and evaluate voluntary disclosure. The enforcement framework specifically contemplates favorable treatment where an acquirer uncovers and discloses misconduct at an acquired business — which turns diligence from a cost into an option worth exercising.
Data analytics: what to actually run
Compliance analytics is often discussed abstractly. Here is a starting battery that any company with an ERP can run, ranked by yield.
Threshold-hugging. Transactions clustered just below an approval threshold. The single highest-yield test in compliance analytics, because it detects deliberate avoidance rather than error.
Vendor master anomalies. Vendors sharing a bank account, address, or tax identifier with an employee. Vendors created and paid within a short window. Vendors with no purchase order history. Vendors with post office box addresses in high-risk jurisdictions.
Payment routing. Payments to a country other than where the vendor is located or the services were performed. Payments to numbered accounts. Changes to vendor bank details, especially shortly before a large payment — which is also the primary fraud vector for business email compromise.
Round numbers. Invoices and payments at exact round amounts, particularly for services.
Duplicate detection. Same amount, same vendor, close dates; or same invoice number with different amounts.
Rebate, discount, and credit outliers. By customer, by salesperson, by region, as a ratio to revenue. Compare to the global distribution and flag the tail.
Expense patterns. Aggregate hospitality per external recipient. Expenses submitted on weekends or holidays in jurisdictions where that is anomalous. Sequential receipt numbers. Approver-beneficiary pairs that recur.
Journal entries. Manual entries posted at period end, by users who do not normally post, to accounts that do not normally receive manual entries, in round amounts.
Sales concentration. Revenue concentrated with a single salesperson-customer pair, particularly where the customer is state-owned.
Two operating principles. First, every analytic needs a disposition workflow — an alert nobody investigates is worse than no alert, because it establishes knowledge. Second, tune for a manageable alert volume and record the tuning decisions; a threshold set to produce a comfortable number of alerts is a decision that should be documented and defensible.
Culture, measured
"Tone at the top" is the most-repeated and least-operationalized phrase in the field. It can be measured, and the measurements are more predictive than most compliance metrics.
Run an anonymous culture survey annually, segmented by region and function, asking:
- Would you report misconduct if you observed it?
- Do you believe something would happen if you did?
- Have you felt pressure to compromise standards to meet a target?
- Do you believe people at senior levels are held to the same standards?
- Do you know how to report?
Read the segments, not the average. A company-wide willingness-to-report score of sixty-five percent that conceals a twenty-six percent score in one region is telling you exactly where the next problem will be.
Watch the trend, especially downward. A decline in reporting volume or in willingness-to-report almost never means misconduct declined. It usually means the workforce learned something — that a reporter was punished, that a report went nowhere, or that a senior person was protected.
Test tone with a middle-manager question, because that is where tone actually operates. Employees do not experience the CEO's values statement; they experience their supervisor's response when a target is at risk. Ask whether their manager has ever told them not to worry about a rule.
The interventions that move these numbers, in order of effect: visible discipline of a senior person; a compliance decision that visibly cost the company revenue; leadership talking about a specific incident rather than about values in the abstract; and a fast, respectful response to a report the reporter can perceive. Values posters and annual training move nothing.
Practice pointers
Make the risk register the spine. Every control, test, training segment, and board agenda item should trace to a row in it. If something in the program does not trace to a risk, ask why you are doing it.
Configure the system before you write the policy. A payment block is worth more than a paragraph.
Give the compliance function read access to the transaction data, and treat any resistance as the finding it is.
Publish response commitments for the reporting channel and meet them. Speed is how the internal channel competes with an award under 15 U.S.C. § 78u-6.
Institute the retaliation review control today. It is the highest ratio of protection to effort in the entire program.
Test the top five controls every year and retest every finding. Then tell the board the exception rate, not the training completion rate.
Run threshold-hugging analytics first. It is the highest-yield test available and it usually requires one query.
Do root cause analysis on every substantiated report, and record the resulting program change. That loop is the element regulators look for and most companies skip.
Discipline upward, and let the organization know that a senior person was disciplined — without the details. Nothing else moves the culture survey.
Verify preservation technically, not by memo, and include personal devices used for business.
Write board minutes that record questions and directions, not attendance.
Assume the program will be evaluated as of the conduct and again as of the charging decision. The second evaluation is the one you can still change, and it is worth a very large amount of money.
Sector overlays worth building in
The core program is the same everywhere; a handful of sector-specific obligations bolt onto it and are frequently missed until an examination.
Government contractors. Mandatory disclosure obligations of credible evidence of certain violations; a written code and program with specified elements as a contract requirement; and 31 U.S.C. § 3729 qui tam exposure that dwarfs most other risks. Suspension and debarment are existential, and the suspension and debarment official's assessment of the program is a separate proceeding from any criminal resolution — with its own standards and its own audience.
Health care. Federal health care program exclusion is a business-ending consequence; the compliance program elements expected by the Office of Inspector General track the Guidelines closely; and corporate integrity agreements are the sector's version of a monitorship, with detailed and enforceable obligations.
Financial institutions. Anti-money laundering program requirements, suspicious activity reporting, sanctions screening obligations, and examination cycles that generate their own findings — with the certification and internal control obligations of 15 U.S.C. § 7241 and 15 U.S.C. § 7262 layered over.
Issuers generally. The FCPA accounting provisions at 15 U.S.C. § 78m impose affirmative books-and-records and internal accounting controls obligations that apply enterprise-wide, whether or not any bribe is alleged. Many resolutions are accounting cases, which makes payment, vendor, and expense classification controls anti-corruption controls in substance.
Companies with EU operations face works council consultation requirements on hotlines and monitoring, data protection constraints on investigations and analytics, and local rules on anonymous reporting. Design the channel and the analytics with these constraints from the start, rather than building a U.S. program and discovering it cannot be deployed in Europe.
Companies with export or sanctions exposure. Screening at order entry rather than shipping; end-use and end-user diligence; classification discipline; and a voluntary disclosure framework with its own mitigation credit that operates independently of the Justice Department's.
Common mistakes
No risk assessment, or one that does not drive anything. The register should be visibly the source of the testing plan, the training plan, and the board agenda.
Policies instead of controls. If the system will process the transaction, the policy is not a control.
Training completion as the headline metric. It measures clicks.
A hotline with no case management. And no published response commitments.
No retaliation control on adverse actions. The cheapest control in the program, and routinely absent.
Compliance with no data access. A function that cannot query cannot detect.
Testing that never finds anything. Either the sample is wrong or nobody is looking.
Findings closed without retesting. A closed finding you did not retest is a finding you decided to believe.
Discipline that stops below the executive level. Regulators, and employees, read this instantly.
Incident description instead of root cause analysis. The former fixes a person; the latter fixes the company.
No preservation capability for messaging applications. The most common cooperation failure in current practice.
Board minutes that record attendance rather than engagement. They are the Caremark evidence, and they are free to write properly.
Treating the program as legal's project. Controls belong to the business; compliance owns the program, not the operations.
Privilege in program work
Routine program operation is not privileged and mostly should not be. The risk register, the control matrix, the training materials, the third-party diligence files, and the operational testing results are business records. Attempting to privilege all of it is unsustainable and damages credibility on the claims that are legitimate.
Investigations are different. Where counsel conducts or directs an investigation for the purpose of providing legal advice, the privilege can attach — and the structure has to be established at the outset. Engagement letters, direction of consultants through counsel, labeling, and restricted distribution all matter, and none of them substitute for the work genuinely being legal in purpose.
Consultant-led assessments. A compliance assessment commissioned by the business is a business record. The same assessment commissioned by counsel to inform legal advice may be protected. Decide which you are doing before the engagement letter is signed, and do not re-characterize later.
Waiver in cooperation. Full cooperation requires producing facts, not necessarily privileged legal analysis, and the distinction is worth preserving deliberately. Produce facts, chronologies, and documents; be careful about producing counsel's mental impressions, and be aware that broad waiver in one forum tends to travel.
Two-track documentation. Keep the operational program record — which you want to be robust, contemporaneous, and unprivileged — separate from investigation work product. Mixing them makes both worse.
Step 10: The annual cycle
| Period | Activity | Owner |
|---|---|---|
| Q1 | Risk assessment refresh; risk register updated | Compliance |
| Q1 | Testing plan built from the register; resourced | Compliance / Internal audit |
| Q1 | Prior-year metrics package to the board committee | Compliance |
| Q2 | Testing wave one; findings and remediation plans | Internal audit |
| Q2 | Third-party diligence refresh for high-risk relationships | Procurement / Compliance |
| Q2 | Targeted training delivered by segment | Compliance |
| Q3 | Testing wave two; retesting of prior findings | Internal audit |
| Q3 | Culture survey | HR / Compliance |
| Q3 | Policy review and update | Legal |
| Q4 | Annual program assessment; gaps and plan for next year | Compliance |
| Q4 | Compensation cycle: compliance modifiers applied; clawback decisions | HR / Compensation committee |
| Q4 | Board deep dive on mission-critical risks | Board |
| Continuous | Report intake, triage, investigation, closure | Compliance |
| Continuous | Retaliation review on adverse actions affecting reporters | Compliance / HR |
| On event | Acquisition integration; new market entry; incident response | Compliance |
Related documents
- Corporate Compliance Programs: The ECCP, Monitorships, and What Regulators Actually Credit
- Compliance Program Effectiveness Checklist: A Practical Checklist
- Compliance Program Toolkit: Risk Assessments, Testing Plans, and Remediation Records
- Conducting an Internal Investigation: Scope, Privilege, and Reporting
- The Foreign Corrupt Practices Act: Anti-Bribery, Books and Records, and Third-Party Risk
- White Collar Criminal Investigations: Grand Jury Subpoenas, Internal Investigations, and Corporate Cooperation
This guide is general information, not legal advice, and does not create an attorney-client relationship.