Compliance Program Documentation Template
Four documents and three sheets that map every regulatory obligation to a control, so gaps and orphan policies both surface before a regulator finds them.
Free download · No account needed
Obligation to Control Map · Millbrace Industrial Supply Inc. · 2026
A policy manual and a real program can look identical in a binder. The map is what tells them apart.
Every row is one regulatory obligation, sourced and risk-tiered, checked against whatever control actually exists. Run the same check in the other direction and a policy that maps to nothing shows up too.
| Obligation | Source | Mapped control | Status |
|---|---|---|---|
| Agent due diligence before engagement | FCPA third-party risk | None | Gap |
| Restricted-party screening at onboarding | OFAC / EAR | None | Gap |
| Dress code and workplace appearance | No obligation on this list | Policy exists | Orphan |
32 obligations, 11 with no control at all, 5 existing policies mapped to none of them
Both numbers come from the same map, run in opposite directions. A checklist that only lists policies never catches the second one.
Most compliance program guidance describes what a program should contain: a code of conduct, a hotline, training, a risk assessment. The Department of Justice's Evaluation of Corporate Compliance Programs asks a sharper question first, whether the program's controls were actually tailored to the risks the organization's own risk assessment identified, not whether a generic list of policy topics exists. A bought manual can satisfy the list and fail that question completely, since nothing about owning a code of conduct proves it was built for this business.
This pack answers the question with one artifact run in both directions. The Obligation to Control Map lists every obligation the risk assessment identifies, sourced to the statute, checked against whatever control exists. In the worked example, 11 of 32 obligations, 34%, have none. Run the map the other way and 5 of the inherited manual's 26 policies map to nothing on the list. The Sentencing Guidelines require prioritizing the response to the risks most likely to occur, and a policy nobody's risk assessment asked for cannot be prioritized against anything.
The same map sets the testing calendar's cadence, quarterly for the highest-risk obligations, annual for the lowest, so testing hours concentrate where the exposure actually sits instead of spreading evenly across every named policy out of habit. Regulatory change is what keeps the obligation list current as a rule amends, and this pack is where the underlying program gets built, tested on that calendar, and tracked to closure on a finding register.
What's in the pack
Obligation to Control Map
Every regulatory obligation the risk assessment identifies, sourced and risk-tiered, checked against the control that covers it, or marked a gap with nothing invented to fill it.
Program Charter
Scope, governance and the three questions a real reviewer asks, well designed, applied in good faith, works in practice, with the artifact that answers each one named.
Policies by Risk Area
Every policy cites the obligation ID it satisfies, so a policy that maps to nothing on the current risk assessment is flagged rather than kept by default.
Training Plan
Audiences and cadence set by risk tier, so the highest-risk roles get more than the once-a-year module everyone else gets.
Testing Procedure
The cadence rule tying testing hours to risk tier, what evidence a test has to pull, and the rule that a finding closes on a retest, never on a reissued policy.
Testing Calendar
The cadence rule applied to the current map: which obligations get tested when, and the hours each cycle actually costs.
Finding Register
Every gap the map surfaces, logged with an owner and a target close date, and closed only once a retest reproduces the evidence the obligation requires.
How to use it
- 1
Open in River, or take it blank
Open the pack in River and describe what the business actually does, where and through whom, or download the Word documents and CSV sheets from the template library and build the map yourself.
- 2
Build the map before writing a single policy
List the specific obligations the risk assessment identifies, sourced and tiered, before drafting anything meant to satisfy them.
- 3
Check existing policies against the map, not just the map against them
A policy that maps to no obligation is spending testing hours on a risk the assessment does not show, at the same time a real gap sits uncovered.
- 4
Let the risk tier set the testing cadence
Quarterly for the highest tier, annual for the lowest, so hours concentrate on the obligations that actually carry enforcement exposure.
Frequently asked questions
Is this template free?
Yes, no account or card required. The download is Word documents and CSV sheets in a zip. Edit with AI is the second half: the agent builds the obligation map from a description of what the business actually does, in both directions.
What am I actually downloading?
Four Word documents and three CSV sheets, zipped. The sheets open in Excel, Numbers or Google Sheets straight off the download, and the charter, policies, training plan and testing procedure open in Word or Pages.
What does mapping obligations to controls in both directions actually catch?
Two different failures. Checking obligations against controls finds gaps, requirements with nothing covering them. Checking controls against obligations finds orphans, policies that exist but address no risk the current assessment actually identifies, and are consuming testing hours on the wrong thing.
We don't have a formal risk assessment yet. Can we still use this?
Yes. Describe what the business actually does, where it sells, through whom, what physical operations it runs, and the obligation list starts from that description. A written risk assessment gets more precise over time; it does not need to exist in final form before the map can start.
Why does the testing cadence differ by obligation instead of one schedule for everything?
Because a uniform schedule spends the same hours on a dress-code policy and a third-party due diligence procedure. Tying cadence to risk tier puts more testing hours on the obligations that carry real enforcement exposure and fewer on the ones that do not, which is what a risk-based program is supposed to do.
How does this fit with the other legal packs?
Regulatory change keeps the obligation list current as a rule amends. This pack is where those obligations get mapped to controls, tested on a calendar, and tracked to closure on a finding register. A privacy-specific obligation often starts on the dedicated privacy pack instead, and once a regulator actually asks about an obligation, the inquiry response pack takes over from there.
The Training Plan sets a cadence by risk tier. How do we prove a specific employee actually completed it?
That per-employee record is a separate artifact from the map. The policy and attestation pack ties each employee's signature to the exact policy version it was given for, so a reissue stales the record instead of leaving an old signature to stand for whatever the policy becomes next.
Map every obligation to its control, in both directions
Take the Word documents and CSV sheets blank, or open this exact pack in River and describe what the business actually does.
Edit with AI