2.4 Documenting the Compliance and Ethics Program: The Compliance Plan, Manual, and Program Charter

Key Takeaways

  • The CCEP Detailed Content Outline lists "Document the compliance and ethics program (e.g., compliance manual/plan)" as a discrete Domain 1 task, separate from maintaining the code of conduct and separate from writing operational policies.
  • A compliance plan describes the program itself — authority, scope, elements, owners, and annual work plan — while policies tell employees how to behave; confusing the two is the most common structural error in program documentation.
  • The written program should map explicitly to the seven FSGO §8B2.1 elements so that a prosecutor, regulator, or new board member can trace each element to a named owner, an artifact, and an evidence source.
  • Version-controlled program documentation is the primary evidence that a program existed and operated at the time of the misconduct, which is exactly the period a DOJ ECCP inquiry examines retrospectively.
  • A program charter approved by the governing authority is what converts delegated CCO authority from an assertion into a governance fact, and it should name the reporting line, budget authority, and unrestricted board access.
Last updated: August 2026

2.4 Documenting the Compliance and Ethics Program

Compliance professionals write a great deal, and it is easy to assume that a thick binder of policies is the documented program. It is not. The Detailed Content Outline treats "Document the compliance and ethics program (e.g., compliance manual/plan)" as its own Domain 1 task, listed separately from maintaining the code of conduct and separately from developing operational policies. The exam tests whether you understand the difference.

Policies describe required behavior. The compliance plan describes the program. A gifts and entertainment policy tells a sales director what she may buy a customer. The compliance plan tells the board who owns the anti-corruption risk, what the compliance function will do about it this year, who approves the budget, how effectiveness will be measured, and which committee receives the report. One is an instruction to the workforce; the other is the operating architecture of the compliance function itself.


1. The Document Set

Most mature programs maintain three distinct program-level artifacts. Smaller organizations legitimately combine them into one document — scalability is a recognized principle — but the content must exist somewhere.

ArtifactAudienceWhat it establishesApproval level
Compliance Program CharterBoard / audit committeeThe compliance function's mandate, independence, reporting line, budget authority, and unrestricted access to records, personnel, and the boardGoverning authority
Compliance Plan / ManualManagement, auditors, regulators, prosecutorsHow the program actually operates: the seven elements, risk areas covered, roles and owners, escalation paths, recordkeeping, and effectiveness measuresCCO, ratified by the oversight committee
Annual Compliance Work PlanCompliance staff, internal audit, executive committeeThe current-year commitments: risk assessment cycle, audits and monitoring, training calendar, policy refresh schedule, remediation milestonesCCO, reported to the board

What Belongs in the Compliance Plan

A defensible compliance plan is organized so that a reader who has never met you can trace the program end to end:

  1. Authority and scope. The legal and regulatory basis for the program, which legal entities and geographies it covers, and how it applies to affiliates, joint ventures, and third parties.
  2. Governance map. Board committee, management compliance committee, CCO, and the business's own control owners — with the reporting cadence for each.
  3. Element-by-element architecture. Each of the seven FSGO §8B2.1 elements, with the owner, the operating artifact, and the evidence source for each.
  4. Risk coverage. The compliance risk areas the program addresses, tied to the enterprise compliance risk assessment.
  5. Recordkeeping and retention. What the program keeps, for how long, and where — because an investigation two years from now will be reconstructed from these records.
  6. Effectiveness measurement. The metrics, review cadence, and independent assessment schedule.
  7. Revision history. Version, approval date, approver, and a summary of what changed.

Mapping the Plan to the Seven Elements

The single most useful table in a compliance plan is the element map. It is what a prosecutor asks for, what a new audit committee chair reads first, and what exposes gaps fastest.

FSGO §8B2.1 ElementProgram OwnerOperating ArtifactEvidence Source
(b)(1) Standards and proceduresCCO / Policy CommitteeCode of conduct; policy library; policy-on-policiesVersion history, attestation records
(b)(2) Governance, oversight, resourcesBoard committee / CCOProgram charter; committee charters; budgetMinutes, executive-session logs, headcount
(b)(3) Due care in delegationHR / ComplianceScreening standard; exclusion checks; delegation of authorityScreening records, DOA matrix
(b)(4) Communication and trainingCompliance / L&DTraining curriculum; communications calendarLMS completion, comprehension scores
(b)(5) Monitoring, auditing, reportingCompliance / Internal AuditAudit plan; monitoring scripts; hotlineAudit reports, case data, trend analysis
(b)(6) Discipline and incentivesHR / Compliance / Comp CommitteeDisciplinary matrix; incentive scorecards; clawback policySanction log, parity analysis
(b)(7) Response and remediationCCOInvestigation protocol; CAP trackerRoot-cause reports, CAP closure evidence

2. Why Documentation Is Evidentiary, Not Administrative

The DOJ Evaluation of Corporate Compliance Programs asks prosecutors to evaluate the program as it existed at the time of the misconduct, not the improved version presented after the fact. That retrospective framing makes version control an evidentiary control:

  • Version-controlled means provable. A plan showing that anti-corruption third-party screening was adopted in March, two months before the payment at issue, is a defense. The same content in an undated file proves nothing.
  • Undocumented programs are treated as absent. Element (b)(2) requires that "high-level personnel" ensure an effective program and that specific individuals be assigned day-to-day operational responsibility. If no document names those individuals, the organization is arguing that an unwritten assignment satisfied a written standard.
  • Gaps you disclose are cheaper than gaps found. A plan that states honestly that distributor auditing begins in Q3 reads as a program under management. A plan that silently omits distributors reads as a program that missed a risk.

Exam Watch — The "we have policies, so we have a documented program" trap. A scenario describes an organization with a polished code of conduct, sixty operational policies, and no compliance plan, charter, or work plan. The best answer is not "write more policies" and not "the documentation is adequate." It is to create the program-level document that ties the existing material to owners, authority, and an annual plan. Policy volume is not program architecture.

Common Documentation Failures

Failure ModeWhat it looks likeConsequence
Policy pile as planHundreds of policies, no program-level documentNo traceable owner or authority for any element
Stale planPlan approved four years ago; program has changed twiceDocumentation contradicts practice; credibility loss
Aspirational planDescribes controls that were never implementedWorse than silence — reads as misrepresentation
Orphaned charterCharter exists but was never board-approvedCCO independence is asserted, not established
No revision historyCurrent version only; prior states unrecoverableCannot prove what the program was at the relevant time

3. Scaling the Documentation

Element (b) of the Guidelines and the ECCP both recognize that program design scales with the size, industry, and risk profile of the organization. A 200-person domestic manufacturer does not need the documentation set of a 60,000-person multinational — but the tasks still have to be assigned to someone in writing.

  • Small organization (under ~500 employees): one combined compliance plan of 10–20 pages incorporating the charter and the annual work plan; a single named compliance officer; annual board approval.
  • Mid-size / multi-site: separate charter and plan; regional appendices for jurisdiction-specific requirements; work plan reviewed semi-annually.
  • Large multinational: enterprise plan plus subsidiary-level implementation plans; local-language versions; documented reconciliation showing local plans do not fall below the enterprise standard.

The scaling error the exam punishes is not "too little documentation for a small company." It is borrowing a large-company document without implementing it — a downloaded template naming committees that do not exist and controls nobody runs.

Loading diagram...
Program Documentation Hierarchy and Approval Flow
Test Your Knowledge

A regional medical device manufacturer has a well-drafted code of conduct, 48 operational policies covering privacy, conflicts of interest, gifts, and record retention, and a full training calendar. During an audit committee meeting, a new independent director asks who is accountable for each element of the compliance program, what the compliance budget is, and what the program committed to accomplish this year. The Chief Compliance Officer cannot point to any single document that answers those questions. What is the most appropriate corrective action?

A
B
C
D
Test Your Knowledge

A company under investigation produces its current compliance manual to federal prosecutors. The manual is comprehensive and describes risk-based third-party screening in detail, but it carries no version history, no approval dates, and no revision log. The screening control it describes was in fact implemented eight months before the conduct at issue. What is the principal weakness of this documentation?

A
B
C
D
Test Your Knowledge

A 180-employee domestic specialty chemicals company is building its first documented compliance program. Its compliance officer downloads a Fortune 100 compliance manual, adapts the company name, and adopts it. The resulting manual describes a five-member regional compliance council, a dedicated compliance analytics team, and quarterly subsidiary attestation cycles — none of which exist. What is the central problem with this approach?

A
B
C
D