2.4 Documenting the Compliance and Ethics Program: The Compliance Plan, Manual, and Program Charter
Key Takeaways
- The CCEP Detailed Content Outline lists "Document the compliance and ethics program (e.g., compliance manual/plan)" as a discrete Domain 1 task, separate from maintaining the code of conduct and separate from writing operational policies.
- A compliance plan describes the program itself — authority, scope, elements, owners, and annual work plan — while policies tell employees how to behave; confusing the two is the most common structural error in program documentation.
- The written program should map explicitly to the seven FSGO §8B2.1 elements so that a prosecutor, regulator, or new board member can trace each element to a named owner, an artifact, and an evidence source.
- Version-controlled program documentation is the primary evidence that a program existed and operated at the time of the misconduct, which is exactly the period a DOJ ECCP inquiry examines retrospectively.
- A program charter approved by the governing authority is what converts delegated CCO authority from an assertion into a governance fact, and it should name the reporting line, budget authority, and unrestricted board access.
2.4 Documenting the Compliance and Ethics Program
Compliance professionals write a great deal, and it is easy to assume that a thick binder of policies is the documented program. It is not. The Detailed Content Outline treats "Document the compliance and ethics program (e.g., compliance manual/plan)" as its own Domain 1 task, listed separately from maintaining the code of conduct and separately from developing operational policies. The exam tests whether you understand the difference.
Policies describe required behavior. The compliance plan describes the program. A gifts and entertainment policy tells a sales director what she may buy a customer. The compliance plan tells the board who owns the anti-corruption risk, what the compliance function will do about it this year, who approves the budget, how effectiveness will be measured, and which committee receives the report. One is an instruction to the workforce; the other is the operating architecture of the compliance function itself.
1. The Document Set
Most mature programs maintain three distinct program-level artifacts. Smaller organizations legitimately combine them into one document — scalability is a recognized principle — but the content must exist somewhere.
| Artifact | Audience | What it establishes | Approval level |
|---|---|---|---|
| Compliance Program Charter | Board / audit committee | The compliance function's mandate, independence, reporting line, budget authority, and unrestricted access to records, personnel, and the board | Governing authority |
| Compliance Plan / Manual | Management, auditors, regulators, prosecutors | How the program actually operates: the seven elements, risk areas covered, roles and owners, escalation paths, recordkeeping, and effectiveness measures | CCO, ratified by the oversight committee |
| Annual Compliance Work Plan | Compliance staff, internal audit, executive committee | The current-year commitments: risk assessment cycle, audits and monitoring, training calendar, policy refresh schedule, remediation milestones | CCO, reported to the board |
What Belongs in the Compliance Plan
A defensible compliance plan is organized so that a reader who has never met you can trace the program end to end:
- Authority and scope. The legal and regulatory basis for the program, which legal entities and geographies it covers, and how it applies to affiliates, joint ventures, and third parties.
- Governance map. Board committee, management compliance committee, CCO, and the business's own control owners — with the reporting cadence for each.
- Element-by-element architecture. Each of the seven FSGO §8B2.1 elements, with the owner, the operating artifact, and the evidence source for each.
- Risk coverage. The compliance risk areas the program addresses, tied to the enterprise compliance risk assessment.
- Recordkeeping and retention. What the program keeps, for how long, and where — because an investigation two years from now will be reconstructed from these records.
- Effectiveness measurement. The metrics, review cadence, and independent assessment schedule.
- Revision history. Version, approval date, approver, and a summary of what changed.
Mapping the Plan to the Seven Elements
The single most useful table in a compliance plan is the element map. It is what a prosecutor asks for, what a new audit committee chair reads first, and what exposes gaps fastest.
| FSGO §8B2.1 Element | Program Owner | Operating Artifact | Evidence Source |
|---|---|---|---|
| (b)(1) Standards and procedures | CCO / Policy Committee | Code of conduct; policy library; policy-on-policies | Version history, attestation records |
| (b)(2) Governance, oversight, resources | Board committee / CCO | Program charter; committee charters; budget | Minutes, executive-session logs, headcount |
| (b)(3) Due care in delegation | HR / Compliance | Screening standard; exclusion checks; delegation of authority | Screening records, DOA matrix |
| (b)(4) Communication and training | Compliance / L&D | Training curriculum; communications calendar | LMS completion, comprehension scores |
| (b)(5) Monitoring, auditing, reporting | Compliance / Internal Audit | Audit plan; monitoring scripts; hotline | Audit reports, case data, trend analysis |
| (b)(6) Discipline and incentives | HR / Compliance / Comp Committee | Disciplinary matrix; incentive scorecards; clawback policy | Sanction log, parity analysis |
| (b)(7) Response and remediation | CCO | Investigation protocol; CAP tracker | Root-cause reports, CAP closure evidence |
2. Why Documentation Is Evidentiary, Not Administrative
The DOJ Evaluation of Corporate Compliance Programs asks prosecutors to evaluate the program as it existed at the time of the misconduct, not the improved version presented after the fact. That retrospective framing makes version control an evidentiary control:
- Version-controlled means provable. A plan showing that anti-corruption third-party screening was adopted in March, two months before the payment at issue, is a defense. The same content in an undated file proves nothing.
- Undocumented programs are treated as absent. Element (b)(2) requires that "high-level personnel" ensure an effective program and that specific individuals be assigned day-to-day operational responsibility. If no document names those individuals, the organization is arguing that an unwritten assignment satisfied a written standard.
- Gaps you disclose are cheaper than gaps found. A plan that states honestly that distributor auditing begins in Q3 reads as a program under management. A plan that silently omits distributors reads as a program that missed a risk.
Exam Watch — The "we have policies, so we have a documented program" trap. A scenario describes an organization with a polished code of conduct, sixty operational policies, and no compliance plan, charter, or work plan. The best answer is not "write more policies" and not "the documentation is adequate." It is to create the program-level document that ties the existing material to owners, authority, and an annual plan. Policy volume is not program architecture.
Common Documentation Failures
| Failure Mode | What it looks like | Consequence |
|---|---|---|
| Policy pile as plan | Hundreds of policies, no program-level document | No traceable owner or authority for any element |
| Stale plan | Plan approved four years ago; program has changed twice | Documentation contradicts practice; credibility loss |
| Aspirational plan | Describes controls that were never implemented | Worse than silence — reads as misrepresentation |
| Orphaned charter | Charter exists but was never board-approved | CCO independence is asserted, not established |
| No revision history | Current version only; prior states unrecoverable | Cannot prove what the program was at the relevant time |
3. Scaling the Documentation
Element (b) of the Guidelines and the ECCP both recognize that program design scales with the size, industry, and risk profile of the organization. A 200-person domestic manufacturer does not need the documentation set of a 60,000-person multinational — but the tasks still have to be assigned to someone in writing.
- Small organization (under ~500 employees): one combined compliance plan of 10–20 pages incorporating the charter and the annual work plan; a single named compliance officer; annual board approval.
- Mid-size / multi-site: separate charter and plan; regional appendices for jurisdiction-specific requirements; work plan reviewed semi-annually.
- Large multinational: enterprise plan plus subsidiary-level implementation plans; local-language versions; documented reconciliation showing local plans do not fall below the enterprise standard.
The scaling error the exam punishes is not "too little documentation for a small company." It is borrowing a large-company document without implementing it — a downloaded template naming committees that do not exist and controls nobody runs.
A regional medical device manufacturer has a well-drafted code of conduct, 48 operational policies covering privacy, conflicts of interest, gifts, and record retention, and a full training calendar. During an audit committee meeting, a new independent director asks who is accountable for each element of the compliance program, what the compliance budget is, and what the program committed to accomplish this year. The Chief Compliance Officer cannot point to any single document that answers those questions. What is the most appropriate corrective action?
A company under investigation produces its current compliance manual to federal prosecutors. The manual is comprehensive and describes risk-based third-party screening in detail, but it carries no version history, no approval dates, and no revision log. The screening control it describes was in fact implemented eight months before the conduct at issue. What is the principal weakness of this documentation?
A 180-employee domestic specialty chemicals company is building its first documented compliance program. Its compliance officer downloads a Fortune 100 compliance manual, adapts the company name, and adopts it. The resulting manual describes a five-member regional compliance council, a dedicated compliance analytics team, and quarterly subsidiary attestation cycles — none of which exist. What is the central problem with this approach?