River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Compliance Program Documentation Template

Four documents and three sheets that map every regulatory obligation to a control, so gaps and orphan policies both surface before a regulator finds them.

Free download  ·  No account needed

Obligation to Control Map  ·  Millbrace Industrial Supply Inc.  ·  2026

A policy manual and a real program can look identical in a binder. The map is what tells them apart.

Every row is one regulatory obligation, sourced and risk-tiered, checked against whatever control actually exists. Run the same check in the other direction and a policy that maps to nothing shows up too.

ObligationSourceMapped controlStatus
Agent due diligence before engagementFCPA third-party riskNoneGap
Restricted-party screening at onboardingOFAC / EARNoneGap
Dress code and workplace appearanceNo obligation on this listPolicy existsOrphan

32 obligations, 11 with no control at all, 5 existing policies mapped to none of them

Both numbers come from the same map, run in opposite directions. A checklist that only lists policies never catches the second one.

Most compliance program guidance describes what a program should contain: a code of conduct, a hotline, training, a risk assessment. The Department of Justice's Evaluation of Corporate Compliance Programs asks a sharper question first, whether the program's controls were actually tailored to the risks the organization's own risk assessment identified, not whether a generic list of policy topics exists. A bought manual can satisfy the list and fail that question completely, since nothing about owning a code of conduct proves it was built for this business.

This pack answers the question with one artifact run in both directions. The Obligation to Control Map lists every obligation the risk assessment identifies, sourced to the statute, checked against whatever control exists. In the worked example, 11 of 32 obligations, 34%, have none. Run the map the other way and 5 of the inherited manual's 26 policies map to nothing on the list. The Sentencing Guidelines require prioritizing the response to the risks most likely to occur, and a policy nobody's risk assessment asked for cannot be prioritized against anything.

The same map sets the testing calendar's cadence, quarterly for the highest-risk obligations, annual for the lowest, so testing hours concentrate where the exposure actually sits instead of spreading evenly across every named policy out of habit. Regulatory change is what keeps the obligation list current as a rule amends, and this pack is where the underlying program gets built, tested on that calendar, and tracked to closure on a finding register.

One map, five risk areas, and the testing hours a generic manual spends in the wrong place

The Obligation to Control Map, the risk tiers, and the Testing Calendar it produces.

Obligation to Control Map (excerpt)

32 obligations across 5 risk areas. Every row is checked against an existing control; every existing policy is checked against the list.

ObligationRisk areaStatus
Export classification before first saleExport / sanctionsGap
Pre-clearance before a trade association meetingAntitrustGap
Forklift operator certificationWorkplace safetyCovered
Board compliance update at least annuallyHorizontalCovered

11 of 32 obligations have no mapped control; 5 of 26 existing policies map to none of the 32

Both figures come off the same sheet. A manual that only lists policies has no way to produce either one.

Risk Tiers

Every obligation's tier sets its testing cadence later. Tiers follow enforcement exposure, not alphabetical order.

TierRisk areasObligations
HighAnti-bribery, export controls and sanctions15
MediumAntitrust5
LowWorkplace safety, horizontal12

15 of 32 obligations, 47%, carry the highest tier

Third-party payments and export exposure outweigh every other risk area on this map combined. That is what sets the testing calendar's shape next.

Testing Calendar

Cadence by tier: quarterly, semi-annual, annual. Hours are real, not estimated after the fact.

TierCadenceHours / year
High (15 obligations)Quarterly180.0h
Medium (5 obligations)Semi-annual25.0h
Low (12 obligations)Annual24.0h

229 hours a year, 79% of them on the High tier

The manual it replaced tested all 26 policies quarterly, 208 hours, with 19% of that spent retesting policies that mapped to nothing. The tailored calendar costs less and points where the exposure actually is.

What's in the pack

01

Obligation to Control Map

Every regulatory obligation the risk assessment identifies, sourced and risk-tiered, checked against the control that covers it, or marked a gap with nothing invented to fill it.

02

Program Charter

Scope, governance and the three questions a real reviewer asks, well designed, applied in good faith, works in practice, with the artifact that answers each one named.

03

Policies by Risk Area

Every policy cites the obligation ID it satisfies, so a policy that maps to nothing on the current risk assessment is flagged rather than kept by default.

04

Training Plan

Audiences and cadence set by risk tier, so the highest-risk roles get more than the once-a-year module everyone else gets.

05

Testing Procedure

The cadence rule tying testing hours to risk tier, what evidence a test has to pull, and the rule that a finding closes on a retest, never on a reissued policy.

06

Testing Calendar

The cadence rule applied to the current map: which obligations get tested when, and the hours each cycle actually costs.

07

Finding Register

Every gap the map surfaces, logged with an owner and a target close date, and closed only once a retest reproduces the evidence the obligation requires.

How to use it

  1. 1

    Open in River, or take it blank

    Open the pack in River and describe what the business actually does, where and through whom, or download the Word documents and CSV sheets from the template library and build the map yourself.

  2. 2

    Build the map before writing a single policy

    List the specific obligations the risk assessment identifies, sourced and tiered, before drafting anything meant to satisfy them.

  3. 3

    Check existing policies against the map, not just the map against them

    A policy that maps to no obligation is spending testing hours on a risk the assessment does not show, at the same time a real gap sits uncovered.

  4. 4

    Let the risk tier set the testing cadence

    Quarterly for the highest tier, annual for the lowest, so hours concentrate on the obligations that actually carry enforcement exposure.

Frequently asked questions

Is this template free?

Yes, no account or card required. The download is Word documents and CSV sheets in a zip. Edit with AI is the second half: the agent builds the obligation map from a description of what the business actually does, in both directions.

What am I actually downloading?

Four Word documents and three CSV sheets, zipped. The sheets open in Excel, Numbers or Google Sheets straight off the download, and the charter, policies, training plan and testing procedure open in Word or Pages.

What does mapping obligations to controls in both directions actually catch?

Two different failures. Checking obligations against controls finds gaps, requirements with nothing covering them. Checking controls against obligations finds orphans, policies that exist but address no risk the current assessment actually identifies, and are consuming testing hours on the wrong thing.

We don't have a formal risk assessment yet. Can we still use this?

Yes. Describe what the business actually does, where it sells, through whom, what physical operations it runs, and the obligation list starts from that description. A written risk assessment gets more precise over time; it does not need to exist in final form before the map can start.

Why does the testing cadence differ by obligation instead of one schedule for everything?

Because a uniform schedule spends the same hours on a dress-code policy and a third-party due diligence procedure. Tying cadence to risk tier puts more testing hours on the obligations that carry real enforcement exposure and fewer on the ones that do not, which is what a risk-based program is supposed to do.

How does this fit with the other legal packs?

Regulatory change keeps the obligation list current as a rule amends. This pack is where those obligations get mapped to controls, tested on a calendar, and tracked to closure on a finding register. A privacy-specific obligation often starts on the dedicated privacy pack instead, and once a regulator actually asks about an obligation, the inquiry response pack takes over from there.

The Training Plan sets a cadence by risk tier. How do we prove a specific employee actually completed it?

That per-employee record is a separate artifact from the map. The policy and attestation pack ties each employee's signature to the exact policy version it was given for, so a reissue stales the record instead of leaving an old signature to stand for whatever the policy becomes next.

Map every obligation to its control, in both directions

Take the Word documents and CSV sheets blank, or open this exact pack in River and describe what the business actually does.

Edit with AI