Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Best Practices for Retaining and Reviewing Compliance DocumentationCompliance documentation is the operational record of how a company identifies, assesses, and controls corruption risk. It can show why a third party was approved, which checks were completed, who authorized a payment, and how an allegation was handled. When records are incomplete or difficult to retrieve, even a well-designed compliance program may be hard to defend. Retention is therefore more than an administrative task. It connects policies, due diligence, training, approvals, investigations, monitoring, and reporting into an evidence trail. A reliable records process helps companies respond to regulators, auditors, internal investigations, acquisition reviews, and business disputes with accurate information. The right approach should be risk-based and practical. Companies need clear ownership, consistent naming and storage rules, defined retention periods, secure access controls, and regular reviews that identify gaps before an incident occurs. Define The Compliance RecordA compliance record includes any document or data that demonstrates how a risk-related decision was made or how a control operated. Common examples include risk assessments, policies, training attendance, gifts and hospitality registers, charitable contribution approvals, third-party questionnaires, sanctions screening results, contracts, invoices, investigation files, whistleblowing reports, and monitoring results. The record may exist in several formats. Email correspondence, instant messages, workflow approvals, spreadsheets, photographs of receipts, meeting minutes, and system logs can all become relevant evidence. A narrow policy that covers only formal reports may leave important decisions undocumented. Create a records inventory that maps each document category to its business process, owner, system, access level, and retention period. The inventory should distinguish between original evidence, working papers, duplicate copies, and convenience records. This prevents teams from retaining everything indefinitely while still protecting material that may be needed later. The inventory should also identify records subject to legal privilege, personal data restrictions, secrecy obligations, or export controls. These categories may require separate handling, restricted access, or advice from qualified counsel. Set Retention Rules By RiskA single retention period for every compliance file is rarely appropriate. The correct period may depend on local law, limitation periods, contractual requirements, tax rules, industry regulation, investigation needs, and the seriousness of the underlying risk. A low-risk training attendance record may require different treatment from an investigation into suspected bribery. A retention schedule should state the minimum period, the event that starts the period, the responsible owner, and the permitted disposal method. For example, a third-party file might be retained for a defined period after the relationship ends, while an investigation file could be retained for a defined period after closure or final legal action. Companies operating across jurisdictions should create a global baseline and then apply local extensions where required. Country risk profiles and local legislation guidance can help compliance teams identify differences in recordkeeping expectations, particularly where privacy, employment, procurement, or anti-money laundering rules apply. Legal holds must override routine deletion. When litigation, an investigation, an audit, or a regulatory request is reasonably anticipated, relevant records should be preserved promptly. The hold should identify affected custodians, systems, date ranges, document types, and responsibilities, with reminders and documented release procedures. Build A Controlled Storage FrameworkA retention policy has little value if records are stored in personal inboxes, unprotected shared drives, or disconnected spreadsheets. Use an approved repository with role-based permissions, encryption, version control, audit trails, and reliable search capabilities. The system should preserve metadata such as the author, creation date, approval history, and modification history. Access should follow a need-to-know principle. Business users may need to confirm that a third party passed due diligence, while only a small investigation team should see interview notes or allegations. Segregated access protects sensitive information and reduces the risk of unauthorized alteration, retaliation, or accidental disclosure. Document naming conventions should be simple enough for consistent use. A useful format can include the business process, counterparty or matter identifier, document type, date, and version. Standard metadata makes it easier to identify duplicates, locate expired records, and produce a complete file during an audit. Electronic retention should include backup and recovery controls. Backups are not a substitute for a records management system, because they may preserve corrupted or obsolete versions without clear context. Test restoration procedures periodically and document how records remain readable when software, storage platforms, or file formats change. Document Decisions And Due DiligenceA strong compliance file explains the decision, not merely the outcome. For third-party onboarding, the file should show the initial risk rating, ownership information, screening results, questionnaire responses, adverse media checks, reference checks, approvals, contract terms, training status, and any conditions imposed before engagement. Risk judgments should be supported by dated evidence. If a company approves a distributor in a high-risk market, the record should explain the rationale, controls, compensation structure, interaction with public officials, use of subcontractors, and level of management approval. If enhanced due diligence was considered unnecessary, that decision should also be documented. Payment records should connect the commercial purpose to the approved arrangement. Maintain invoices, purchase orders, proof of services, expense support, bank details, payment approvals, and evidence that deliverables were received. Unusual commissions, vague descriptions, round-dollar payments, offshore accounts, or requests for cash deserve documented review and escalation. The concept of an improper benefit can be broader than a direct cash payment, which is why teams should understand the UNCAC undue advantage in the context of gifts, favors, employment opportunities, contracts, and other benefits. Clear records help reviewers assess the facts rather than relying on assumptions or incomplete recollections. Review Records For Quality And GapsPeriodic review should test whether records are complete, accurate, current, and retrievable. Sampling can be organized by country, business unit, third-party risk tier, transaction type, or control owner. High-risk categories should receive more frequent and deeper review than low-risk administrative files. A reviewer should ask whether the file supports five basic questions: What happened? Who was involved? What risk was identified? What approval or control was applied? What evidence confirms that the control operated? Missing answers should be recorded as findings with owners and deadlines. Reviewers should also test for inconsistencies. Examples include a contract dated before due diligence approval, payments that exceed approved compensation, expired screening results, training assigned after a third party began work, or an investigation closed without documented remediation. These inconsistencies may indicate a process failure even when individual documents appear complete. Use review results to improve workflows, templates, training, and system controls. If employees repeatedly omit beneficial ownership information, the onboarding form may need mandatory fields. If approvals are routinely captured in email, an automated workflow may create a clearer and more durable audit trail.
Protect Sensitive And Personal InformationCompliance records often contain identity documents, bank information, allegations, interview notes, medical details, or information about political exposure. Retention must be balanced with data minimization. Keep what is necessary to demonstrate compliance, but avoid collecting or retaining unrelated personal information. Classify records according to sensitivity and define who may view, download, edit, or delete them. Investigation materials may require additional safeguards, including restricted folders, separate encryption keys, and a documented protocol for sharing information with counsel, auditors, regulators, or law enforcement. Cross-border transfers require particular attention. A centralized compliance platform may move personal data between jurisdictions, while local laws may impose conditions on hosting, employee monitoring, or access from another country. Privacy assessments and transfer safeguards should be documented alongside the relevant compliance process. Disposal should be deliberate and verifiable. When the retention period expires and no legal hold applies, use secure deletion, shredding, or approved destruction methods. Keep a destruction log with the record category, date, authority, and responsible person, without preserving unnecessary copies of the destroyed content. Assign Ownership And Test The ProgramAccountability should be distributed across compliance, legal, information security, records management, finance, procurement, human resources, and business leadership. A central compliance team can set standards, but process owners are usually best placed to ensure that records are created at the right time and stored in the right location. Training should explain what employees must retain, where records belong, how to correct errors, and when informal communications may become evidence. Short, scenario-based guidance is often more effective than a long policy. Managers should understand that approving a transaction also creates responsibility for maintaining the supporting record. A practical governance cycle may include quarterly checks of high-risk processes, annual review of the retention schedule, periodic access recertification, and an independent assessment of the records framework. Metrics can include overdue due diligence files, missing approval fields, retrieval time, unresolved review findings, and the percentage of records held outside approved systems. Businesses that need help locating relevant compliance resources can use the anti-corruption resource portal for country information, training materials, due diligence guidance, legislation references, and compliance terminology. These resources can support policy updates and help local teams apply consistent standards across markets. Actions That Strengthen Records Management
A defensible documentation program grows from daily habits: recording decisions promptly, preserving supporting evidence, restricting access appropriately, and correcting gaps before they become material. Start by inventorying current records, identifying the highest-risk weaknesses, and agreeing on a small set of measurable controls. For tailored questions about compliance resources, country guidance, or available tools, contact the portal team and put the improved framework into practice across the business. |