RegTech Reviews

Compliance Framework Template for a New Compliance Program

Compliance programs fail at the joints, not because of bad parts.

Senior Writer · · 12 min read
Cover illustration for “Compliance Framework Template for a New Compliance Program”
Compliance Frameworks · September 8, 2026 · 12 min read · 2,724 words

Their connections, not their parts, are where compliance programs fail. Prosecutors dig into the cracks first, like policies that sit unused, a phone line no one calls, or a 2019 risk check gathering dust, since that’s where things fall apart. This piece examines the seven components that make a compliance framework defensible, based on the three sources that determine "effective" here, and considers what happens when each is absent.

Begin with the money, because that’s where most executives begin too, often looking a bit sick. The Ponemon Institute and Globalscape's 2017 study, the most recent of its kind, means the dollar figures should be seen as a minimum, not a maximum. They found the average cost of maintaining compliance at $5.47 million against $14.82 million for the average cost of non-compliance, a 2.71 times multiplier favoring the boring, unglamorous work of doing things right. Both types of costs have likely risen since then, but remember the ratio, not the exact figures.

It hasn't changed direction. Recent data shows 85% of firms say compliance grew harder in the last three years, and 65% think costs will rise in the next. Enforcement isn't letting up: Thomson Reuters Regulatory Intelligence put global non-compliance fines at $14 billion in 2024, driven mainly by insider trading, anti-money-laundering failures, and poor oversight. In fiscal year 2024, the SEC by itself ordered $8.2 billion in financial remedies. Those aren't abstractions. They're what it looks like when the joints give.

There's an upside too. The SEC says companies that self-report and fix issues can have civil penalties reduced or even eliminated; such a program also helps avoid punishment and shows investors and partners the company finds its errors before regulators do. New businesses get one chance to set up their program correctly, and most founders underestimate its importance. Fixing a flawed system after the fact is pricier and harms trust more than doing it right initially. That's the real reason to read the next seven sections before you start any policy documents.

The authoritative sources that define what an effective compliance program must contain

Three documents shape nearly all compliance programs, and most failures happen because companies ignore one and rely on guesswork. Anyone who knows these three sees the same thing every time: thrown together by guesses, leaving out the rule that really matters. If a company's counsel can't name which of the three its program was built against, that's not a paperwork gap. That defines it.

First published in 1991, the U.S. Federal Sentencing Guidelines for Organizations is the primary text, and it takes precedence over all others on this list. Chapter 8 sets out the Seven Elements of an Effective Compliance Program, backed by a stark incentive: if convicted, a company with a proven program can cut its fines by as much as 95%. That's not a rounding error. A fine could either destroy a company or just leave it damaged but still operating. Section 8B2.1(c) also makes risk assessment a formal requirement rather than a suggestion, directing organizations to periodically evaluate the likelihood and seriousness of potential criminal conduct. The FSGO sets up this entire process with two goals: to prevent criminal conduct through due diligence, and to build an ethical culture stronger than any policy on a shared drive.

The DOJ's Evaluation of Corporate Compliance Programs, updated September 23, 2024, is the prosecutor's actual working document, the one used mid-investigation to judge whether a program is real or decorative. A program that scores well under the ECCP tends to get a better resolution when things go wrong. The 2024 update included three new focus areas: AI and emerging technology risk, ongoing monitoring through data analytics, and whistleblower protections. The DOJ now expects risk assessments to be dynamic and responsive to business changes. Prosecutors now expect frameworks to adapt as the business changes, and they check if a company has incorporated lessons from past issues into its policies and training. In November 2024, the DOJ's Antitrust Division added guidance, saying programs must address misconduct specific to each business (bid-rigging, price-fixing, etc.), not generic templates for any industry.

ISO 37301:2021 is the international standard for compliance management systems. Here’s the rewrite:

What sets it apart: ISO 37301 can be certified by official auditors, just like a quality management system. It covers public, private, and non-profit groups. It uses the Plan-Do-Check-Act cycle, with leadership and governance seen as essential, not merely cosmetic. Two related standards complete it: Related standards address performance evaluation and competence requirements.

These sources have more in common than they have differences, and using them as separate tasks often results in a compliance department having three conflicting binders. The FSGO's seven elements, the ECCP's investigative questions, and ISO 37301's management system requirements share common underlying components, so this piece combines all three into a single template.

Written policies, procedures, and a code of conduct as the program's foundation

All compliance programs begin with written words, regardless of personal opinions. Organizational values are plainly set by the code of conduct, and specific policies turn them into rules staff in accounts payable or field sales can truly follow any day.

Guidelines from the DOJ and HHS OIG require key elements including conflict handling and reporting mechanisms, staff, contractors, and agents alike. More programs stumble on that last point than necessary. A policy stuck on an internal intranet that's inaccessible to those outside headquarters isn't actually a policy. It’s just a PDF that means well but can’t be reached.

Understanding matters as much as scope, if not more. Lawyers writing policies just for other lawyers creates problems when a warehouse supervisor faces a suspicious shipment. Legal accuracy isn't the same as being useful, and compliance teams focused only on the former make documents for auditors, not workers. The DOJ's ECCP expects policies to be regularly reviewed and updated, no matter what the document claims. It seems obvious that policies must adapt to business changes, but audits often find this missing.

Many firms reverse the order, but A sound approach requires organizations to first identify compliance obligations before documenting controls, not the reverse. The analysis produces the written policies, not the other way around. Skipping the analysis and starting with the document leaves companies with binders of rules that, while well-written, lack real obligation and fail when tested. A good template includes a policy list tied to legal requirements, the code of conduct, yearly reviews, and a revision log for auditors to track changes and reasons.

The compliance officer and committee structure that gives the program its authority

Someone has to own this, and "someone" can't be a title bolted onto an already-full job description, the way a lot of mid-size companies hand compliance to whoever's already running HR. The FSGO and HHS OIG require a designated compliance officer with authority and resources, not just a title on an ignored org chart.

This usually goes wrong at the reporting line: A compliance officer's independence may be compromised if they report through legal or finance. Legal and finance departments may have conflicts of interest when compliance issues affect their work, meaning the officer isn't independent from the start. That setup is wrong, yet it’s the one seen most often. Or the officer might need approval from others before starting an investigation. Or perhaps there's simply no budget for it. The DOJ's 2024 ECCP guidance emphasizes that compliance programs should have adequate funding, and to watch for funding imbalances that may undermine compliance effectiveness.

The committee is above the officer, overseeing their work and making sure problems get fixed, not just recorded. Here’s the rewrite:

Their FY2025 plan shows how it’s done: a Chief Compliance Officer backed by a Clinical Compliance Oversight Committee, checking in every quarter with the Board’s Audit, Risk, and Compliance Committee. That's a reporting schedule that matters, not an annual update that's forgotten by the afternoon.

ISO 37301 says leadership commitment is key to the whole Plan-Do-Check-Act cycle, and the officer-plus-committee setup is how that commitment is put into action every day, not just stated once in a mission statement and then ignored. The checklist includes: a compliance officer job description with explicit written authority, a committee charter, a set reporting cadence to the board, and a real, standalone budget line.

Risk assessment as the process that makes the rest of the program specific rather than generic

Did they tailor these policies for the business's real risks, or just grab a template to meet Friday's deadline? Many programs satisfy generic checklists yet fail to address the one exposure that would truly ruin them. Just say it: using a checklist for compliance, designed for auditors instead of real risks, is worse than nothing since it fakes careful work without doing it.

The FSGO makes this mandatory. Section 8B2.1(c) mandates organizations regularly assess criminal conduct risk and adapt the program accordingly. The assessment must consider the seriousness of potential conduct, its likelihood, and the organization's history.

The DOJ's 2024 move to dynamic risk assessment sets a higher standard. Using last year's risk assessment with just a new date won't meet the standard anymore, which matters since it's the shortcut most compliance teams use. Prosecutors expect the assessment to mirror the business's current state, including new AI adoption risks, and to be prompted by actual operational shifts, not just a new year. Lessons from the company's own past incidents, and from enforcement actions against peers in the same industry, are expected to feed back into the assessment instead of sitting in a folder nobody opens again.

A proper risk assessment yields a list of the most probable and significant risks facing the business, prioritized along with the policies, controls, and training that need the most urgent attention. Regulators look just as hard at how you got the number as at the number. ISO 37301 uses the Plan-Do-Check-Act cycle, requiring organizations to identify compliance obligations and assess risk before creating controls, which tailors a management system to the business. The checklist: a written methodology, a risk register with likelihood and severity ratings, named owners for each risk, and a reassessment schedule that isn't just "sometime next year, probably."

Training and education programs that turn written standards into understood behavior

If no one gets the policy, it's like having no policy at all. This explains why training is a required element, and it's also why "effective" matters in both the FSGO and the ECCP, not "completed" or "attended."

Per DOJ rules, training fits the job and risks each person faces. The most common failure on this list is one worth highlighting: using a single generic module for the entire workforce, regardless of job function, meets the requirement technically but entirely misses its intent. Anyone can spot it easily if they know where to look, since it appears as the same training completion rates in departments with very different risk levels. Procurement and reception shouldn't match in training stats; if they do, the training wasn't customized. The DOJ's Antitrust Division's November 2024 guidance pushes companies to use real data to design training and identify gaps, ensuring training adapts to monitoring findings rather than following a rigid yearly schedule. The 2024 ECCP update says training should learn from past incidents, both in the company and its industry.

For a new program, the practical shape usually stacks four layers: initial training at onboarding for everyone, annual recertification tied to the code of conduct, role-specific training for higher-risk functions like finance, procurement, sales, or anyone touching sensitive data, and training extended to third-party contractors and agents wherever they fall inside the program's scope. ISO 37302 evaluates training performance separately, showing that merely tracking who clicked which slide deck isn't the standard for serious compliance.

Content is important, but so is documentation. Training records must prove completion clearly, and curricula should have versions and dates so the program can show exactly what was taught and when, even after months or years. The checklist includes a training matrix sorted by role and risk, a schedule for delivery, a system to track completion, and a curriculum review cycle linked to policy updates.

Communication channels that make it safe and practical to report concerns

All the above is irrelevant if someone who sees an issue has no safe way to report it. The FSGO's requirement for effective communication channels means something specific: channels that reach employees in a form they'll actually use, not a policy that says a channel technically exists somewhere in a handbook.

The DOJ's 2024 ECCP sees whistleblower programs as a core part of compliance, not just an add-on for show. In the DOJ's own words, a good whistleblower system is key to finding misconduct, encouraging internal reports before regulators step in, and fixing issues promptly instead of letting them linger.

Most of the time, it’s a compliance hotline, often outsourced so workers believe it’s truly anonymous, plus other options like email, face-to-face, or an online form, letting people choose what works for them. Employees must know the channels are available, know how to use them, and have some idea what happens next. If no one knows about a channel, it might as well not be there, and most programs miss this part because setting up the hotline is simple, but reminding people about it often in a memorable way takes real effort. It's worth asking: does the workforce know the hotline number, or is it buried in an old onboarding slide nobody's seen in years?

Costs matter here as well. IBM’s 2023 Cost of a Data Breach Report showed regulatory non-compliance added almost $220,000 in average costs compared to compliant breaches. Spotting issues fast, before they turn into breaches or fines, saves real money, enough to show up on the books if you track it. Weill Cornell Medicine's hotline connects straight to a formal process for investigating and resolving issues, overseen by the compliance officer, ensuring reports don't get ignored. To be compliant, you'll need: a hotline vendor or internal system, multiple reporting channels, a published process for handling reports, and clear communication to your workforce.

Auditing and monitoring systems that give the program ongoing visibility into what is actually happening

People often mix up monitoring and auditing, but the FSGO makes a point of separating them since they serve different purposes. Monitoring continuously checks transactions, records, and behavior against policy standards, running in the background like a wired-in smoke detector. Auditing means regularly examining a certain risk area closely to see if the controls work in practice, not just in theory.

The outdated approach should be phased out, and for good reason: checking once a quarter only finds problems after they’ve happened, not before. The DOJ's 2024 data analytics leaves that model entirely behind. Firms must now treat data analytics like a running dashboard, spotting issues as they happen rather than digging through old records. Prosecutors check if the compliance team can actually get the data it needs, or if it's cut off from the operational systems that have the real information, a problem more common than most programs acknowledge. They also verify if monitoring results feed into risk assessments and policy updates to complete the improvement cycle, and if staffing and technology are enough to operate the function genuinely instead of just meeting the requirement in name only.

Weill Cornell Medicine's program names this element outright: "System for Auditing, Routine Monitoring, and Identification of Compliance Risks," building proactive risk identification directly into the monitoring function instead of treating it as a separate task tacked on afterward. ISO 37302's five-level maturity scale, covering data acquisition, evaluation processes, and reporting, offers a useful benchmark for a new program trying to figure out how sophisticated its monitoring setup needs to be on day one versus where it might grow toward over several years.

The final checklist: a monitoring plan with set frequency and scope per risk area, an audit schedule, data access agreements to ensure compliance can reach needed systems, a standard format for reporting findings, and a clear path from monitoring results to corrective actions. Regulators most closely check that last link, from finding to fix, yet programs often leave it dangling. This is the point the entire piece has been making. Regulators don't rate a compliance program based on its paperwork. They judge it by whether the seven parts really link up when a problem happens.

More in Compliance Frameworks