Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
How to write a compliance memo that protects your company in courtA compliance memo can become a crucial piece of evidence when regulators, prosecutors, shareholders, or business partners examine a company’s conduct. It may show that management identified a legal risk, sought informed advice, evaluated available facts, and took reasonable steps to prevent misconduct. It may also expose weaknesses if it is vague, careless, speculative, or written to create the appearance of compliance after an event. The strongest memo is therefore more than an internal summary. It is a contemporaneous record of a disciplined decision-making process. Its purpose is to help people act lawfully, preserve relevant information, assign responsibility, and demonstrate that the company treated compliance as an operational priority. A defensible document must still be accurate, proportionate, and appropriately protected by legal professional privilege where applicable. Privilege rules differ across jurisdictions, and a memo is not automatically protected merely because a lawyer helped prepare it. The document should be drafted with its possible future audience in mind, including investigators, courts, auditors, and opposing counsel. Define the memo’s legal and business purposeBegin by stating why the memo exists. A clear purpose might be to assess third-party corruption risk before appointing a distributor, document a response to a whistleblower report, interpret a new sanctions requirement, or recommend controls for a government-facing project. Avoid broad language such as “review compliance” when a more precise description is available. The purpose should identify the decision that needs to be made and the legal or policy standards relevant to it. For example, a procurement memo may address anti-bribery laws, conflicts of interest, gifts and hospitality rules, competition concerns, accounting controls, and the company’s code of conduct. A focused scope prevents the document from making unsupported statements about issues that were never investigated. Explain who requested the analysis, who prepared it, and the intended audience. Distinguish between legal advice, factual investigation, business recommendations, and operational instructions. If outside counsel is involved, the document should accurately reflect that role rather than implying that every part of the memo is legal advice. A useful disclaimer may clarify that general resources do not replace advice tailored to the company’s facts. When relying on external compliance material, review the site disclaimer and record the date on which the source was accessed. That small step helps demonstrate source discipline and avoids presenting general information as a definitive legal opinion. Build the factual record before drawing conclusionsCourts tend to examine the facts supporting a decision, not just the confidence of the final recommendation. Create a short factual background section that identifies relevant people, entities, locations, dates, transactions, contracts, payments, approvals, and communications. Separate confirmed facts from allegations, assumptions, and information that remains unverified. Use neutral language. “The distributor requested a success fee equal to 12% of the contract value” is stronger than “The distributor demanded a bribe,” unless the evidence establishes that characterization. Neutral drafting reduces the risk of defamation, overstatement, and premature conclusions while allowing decision-makers to understand the seriousness of the issue. Cite the source of material facts. Sources may include contracts, invoices, accounting entries, interview notes, due diligence questionnaires, corporate registry records, emails, training records, and investigation reports. A concise evidence register can identify each source, its date, its owner, and the proposition it supports. Preserve originals according to the legal hold and document retention requirements. Country and sector context can change the risk assessment. A company operating across multiple jurisdictions should consult current country risk profiles and record how country conditions affected the analysis. General corruption indicators should inform questions and controls, but they should not be treated as proof that a specific individual or company acted improperly. Analyze risk with a traceable methodA persuasive compliance memo connects facts to standards through explicit reasoning. Identify the applicable laws, regulations, contractual obligations, internal policies, and recognized control expectations. Then explain how each standard applies to the facts. Avoid copying legal provisions without translating them into practical implications for the decision under review. Risk analysis should cover conduct, parties, geography, payment flows, decision-makers, and control failures. In an anti-corruption assessment, consider whether a public official or state-owned enterprise is involved, whether an intermediary has a legitimate role, whether compensation is commercially reasonable, and whether services can be verified. Review the approval path and accounting treatment as carefully as the proposed transaction itself. Use a consistent rating method and explain the basis for each rating. A high-risk assessment might result from several moderate indicators that reinforce one another: an opaque ownership structure, a government customer, a request for payment through an unrelated account, and resistance to contractual audit rights. The memo should identify which facts drive the rating and what additional information could change it. The following framework can help distinguish a documented assessment from an unsupported impression:
Address uncertainty without weakening the recordA court may view acknowledged uncertainty more favorably than false certainty. State what the review did not establish, what records were unavailable, and which assumptions shaped the recommendation. If an interview was not conducted, say so. If beneficial ownership could not be independently verified, identify the missing evidence and explain whether the transaction should pause until verification occurs. Use carefully calibrated conclusions. Terms such as “may,” “could,” and “based on the information reviewed” are appropriate when evidence is incomplete, but they should not become a way to avoid making a decision. The memo should still state whether the current information supports approval, conditional approval, escalation, suspension, or rejection. Set out alternative outcomes. For example, a company may proceed only if the intermediary provides verified ownership information, accepts anti-corruption clauses, submits to audit, completes training, uses a transparent bank account, and receives compensation supported by documented services. If those conditions are not met by a specified date, the recommendation should identify the next step. Do not use the memo to speculate about criminal intent or assign blame before an investigation is complete. Distinguish a control deficiency from misconduct and an allegation from a finding. This protects the integrity of the review and helps prevent the document from being used to show that the company reached a predetermined result. Convert analysis into accountable controlsA memo protects the company more effectively when it leads to measurable action. Every recommendation should identify an owner, a deadline, the required evidence of completion, and the escalation route if the action is not completed. “Enhance due diligence” is too vague; “Compliance must obtain certified ownership documents and complete adverse-media screening before the procurement committee votes” is operational. Address the full control environment. Depending on the risk, controls may include enhanced due diligence, segregation of duties, approval by a senior committee, beneficial ownership verification, payment restrictions, conflict-of-interest certifications, employee training, transaction testing, audit rights, and termination provisions. Controls should match the identified risk rather than create unnecessary administrative burden. For transactions involving healthcare, public procurement, or medical products, analyze the pressure points around tenders, clinical evaluations, distributor selection, donations, consulting arrangements, travel, samples, and post-market services. Sector-specific research on healthcare procurement risks can help a memo address risks that a generic third-party checklist may overlook. Record management’s decision separately from the analyst’s recommendation where possible. The decision record should state who approved the action, what conditions were imposed, and whether any deviation from policy was authorized. If an exception is granted, document its business rationale, duration, compensating controls, and approval authority. Preserve privilege, integrity, and usabilityDrafting technique matters. Keep factual findings, legal analysis, and business advice organized in separate sections. Avoid inflammatory descriptions, casual comments, humor, rhetorical speculation, and language suggesting that the document was created to “cover” the company. Assume that every sentence could be read aloud in litigation. Privilege requires special care. Marking a document “privileged and confidential” does not create privilege, and copying a lawyer on an email does not automatically protect the contents. Follow the company’s legal department protocol, limit distribution to people with a genuine need to know, and obtain jurisdiction-specific advice about investigations, mixed-purpose communications, and waiver risks. Use version control and maintain an approval record. The final memo should show its date, author, reviewers, sources, and status. If the facts change, issue a dated supplement or revised assessment instead of silently altering the original. Retain drafts according to counsel’s instructions and avoid deleting relevant material after a complaint, investigation, audit, or anticipated dispute arises. Before circulation, conduct a quality review:
A final reader should be able to understand what happened, why the issue mattered, how the company evaluated it, who made the decision, and what happened afterward. That clarity is valuable for daily compliance management and for later demonstrating that the company acted responsibly. The best compliance memo is a living control document rather than a file prepared once and forgotten. Track whether conditions were completed, test whether controls operated as intended, and update the risk assessment when ownership, law, geography, counterparties, or payment arrangements change. A well-maintained record can show a consistent culture of prevention, detection, and correction. Use this approach for the next significant compliance decision: define the purpose, verify the facts, apply a transparent risk method, document uncertainty, assign controls, and preserve the record properly. When legal exposure is material, have qualified counsel review the memo and the surrounding process before the company acts. |