Corporate Compliance Manual - New York
Corporate Compliance Manual - New York
New York Rider Development Checklist
Before adoption, counsel should identify the New York laws, regulations, licenses, permits, orders, and agency guidance that actually apply to the Company's workforce, products, services, locations, data, industry, and government interactions. This file is not stamped as fully verified until each state-specific control is grounded in current official authority.
☐ New York entity and governance obligations mapped
☐ Employment, leave, wage-hour, safety, and whistleblower rules mapped
☐ Privacy, security, breach, consumer-protection, and marketing rules mapped
☐ Environmental, licensing, professional, and industry rules mapped
☐ State procurement, lobbying, ethics, and government-interaction rules mapped
☐ Record-retention, reporting, notice, and training deadlines mapped
Adoption and Document Control
This Corporate Compliance Manual (the “Manual”) is adopted by [COMPANY LEGAL NAME] (the “Company”) effective [__/__/____]. It establishes the Company's compliance-program framework. It does not replace the laws, regulations, licenses, contracts, collective-bargaining obligations, or more specific policies that apply to a particular business, person, location, or transaction.
| Field | Entry |
|---|---|
| Document owner | [________________________________] |
| Approved by | [________________________________] |
| Effective date | [__/__/____] |
| Version | [________________________________] |
| Next review date | [__/__/____] |
| Applies to | [________________________________] |
| Supersedes | [________________________________] |
| Related code of conduct | [________________________________] |
1. Purpose and Program Principles
The Company's compliance program will be designed and operated in light of its actual risk profile, including its size, industry, geographic footprint, business model, regulatory environment, customers, workforce, technology, transactions, and use of third parties.
The program will be evaluated against three practical questions adapted from current U.S. Department of Justice guidance:
- Is the program well designed?
- Is the program adequately resourced, empowered, and applied in good faith?
- Does the program work in practice?
The Company's objectives are to:
- identify and assess legal and compliance risk;
- prevent and detect misconduct;
- provide accessible advice and reporting channels;
- investigate concerns fairly and consistently;
- remediate root causes and control weaknesses;
- apply incentives and discipline consistently; and
- improve the program using testing, data, lessons learned, and changes in risk.
2. Scope and Responsibilities
2.1 Covered Persons
This Manual applies to the following persons to the extent stated in their applicable policy, agreement, or appointment:
☐ Directors
☐ Officers
☐ Employees
☐ Temporary workers
☐ Contractors and consultants
☐ Agents and intermediaries
☐ Controlled subsidiaries
☐ Joint ventures or other affiliates: [________________________________]
2.2 Board or Governing Body
The Board or designated committee will:
- approve the compliance-program charter and material changes;
- oversee the program and receive periodic reporting;
- review significant misconduct, remediation, resources, and program limitations;
- ensure the compliance function has appropriate access and escalation rights; and
- document decisions concerning material compliance risks.
2.3 Chief Compliance Officer
The Chief Compliance Officer (“CCO”) will:
- administer this Manual and the compliance work plan;
- maintain direct access to the Board or responsible committee;
- coordinate risk assessment, policies, training, reporting, investigations, monitoring, and remediation;
- escalate material issues without improper interference; and
- report resource, data-access, staffing, authority, or independence limitations.
CCO: [________________________________]
Board reporting line: [________________________________]
Administrative reporting line: [________________________________]
2.4 Business and Control Functions
Business leaders own compliance risk in their operations. Legal, human resources, finance, internal audit, information security, privacy, quality, and other control functions retain their assigned responsibilities and will coordinate to avoid gaps or duplication.
3. Compliance Risk Assessment
3.1 Risk Identification
The Company will identify relevant risks using sources such as:
☐ Applicable laws, regulations, licenses, permits, and orders
☐ Products, services, customers, and distribution channels
☐ Countries, government touchpoints, and cross-border activity
☐ Third parties, agents, distributors, vendors, and joint ventures
☐ Gifts, travel, entertainment, donations, sponsorships, and political activity
☐ Complaints, hotline data, investigations, litigation, and enforcement trends
☐ Audit findings, control failures, exceptions, and losses
☐ Mergers, acquisitions, integrations, and divestitures
☐ Personal devices, messaging applications, and record preservation
☐ Artificial intelligence and other emerging technology
☐ Workforce, compensation, sales targets, and incentive structures
3.2 Risk Register
| Risk | Applicable authority | Business owner | Inherent risk | Key controls | Residual risk | Action |
|---|---|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
3.3 Review Cadence
Scheduled review: [MONTHLY / QUARTERLY / ANNUALLY / OTHER]
Event-driven triggers:
☐ New law or enforcement development
☐ New product, market, technology, or business model
☐ Acquisition, joint venture, or major third party
☐ Significant allegation, control failure, or enforcement contact
☐ Material change in data, systems, workforce, or geography
4. Policies, Procedures, and Controls
The Company will maintain risk-based policies and procedures that are current, accessible, understandable, translated where appropriate, and integrated into operational controls.
| Policy domain | Applicability confirmed | Owner | Current version | Training required | Control testing |
|---|---|---|---|---|---|
| Anti-bribery and corruption | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Conflicts, gifts, and entertainment | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Competition and antitrust | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Trade controls and sanctions | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Privacy and cybersecurity | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Employment and workplace conduct | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Financial reporting and records | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Government contracting | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Consumer protection and marketing | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Environmental, health, and safety | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
| Industry-specific requirements | ☐ | [________________________________] | [________________________________] | ☐ | [________________________________] |
Each policy owner will document approval, version control, exceptions, implementation responsibility, and the evidence used to test operation in practice.
5. Training, Advice, and Communications
5.1 Training Plan
Training will be tailored to role and risk. The Company will not assume that annual general training alone is sufficient.
| Audience | Risk or topic | Format and language | Due date | Assessment | Effectiveness measure |
|---|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [__/__/____] | [________________________________] | [________________________________] |
| [________________________________] | [________________________________] | [________________________________] | [__/__/____] | [________________________________] | [________________________________] |
5.2 Advice Channels
Covered Persons may seek compliance advice through:
- [COMPLIANCE EMAIL OR PORTAL]
- [LEGAL CONTACT]
- [MANAGER OR CONTROL FUNCTION]
- [OTHER CHANNEL]
Guidance on recurring questions will be documented and incorporated into policies, training, or controls where appropriate.
6. Reporting and Non-Retaliation
6.1 Reporting Channels
The Company provides the following channels:
☐ Confidential hotline: [________________________________]
☐ Web portal: [________________________________]
☐ Compliance or legal: [________________________________]
☐ Human resources: [________________________________]
☐ Manager or designated officer: [________________________________]
☐ Anonymous reporting where permitted: [________________________________]
6.2 Protection and Escalation
Retaliation for a protected report or other protected activity is prohibited to the extent required by applicable law and Company policy. Reports involving senior management, the compliance function, financial reporting, obstruction, retaliation, or other designated high-risk matters will follow an independent escalation path.
No person may use this Manual, a confidentiality agreement, or another Company measure to impede an individual from communicating directly with SEC staff about a possible securities-law violation, as provided in 17 C.F.R. § 240.21F-17.
If 18 U.S.C. § 1514A applies, the Company will not discharge, demote, suspend, threaten, harass, or otherwise discriminate against an employee because of activity protected by that section.
Retaliation escalation contact: [________________________________]
7. Investigations and Response
7.1 Triage
Each report will be logged and assessed for:
☐ Immediate safety, data, financial, or evidence risk
☐ Investigator independence and conflicts
☐ Need for legal, privilege, labor, privacy, or regulatory review
☐ Mandatory reporting or notification deadlines
☐ Preservation and legal-hold requirements
☐ Senior-management or Board escalation
7.2 Investigation Plan
| Field | Entry |
|---|---|
| Matter number | [________________________________] |
| Allegation | [________________________________] |
| Investigator | [________________________________] |
| Scope | [________________________________] |
| Custodians and data sources | [________________________________] |
| Milestones | [________________________________] |
| Reporting line | [________________________________] |
Investigations will be appropriately scoped, conducted by qualified and objective personnel, documented, and concluded using the applicable evidentiary and decision standard.
7.3 Findings and Remediation
The response will address, as appropriate:
- facts and responsible persons;
- root causes and control failures;
- prior warning signs or missed opportunities;
- disciplinary consistency;
- restitution, recovery, disclosure, or notification decisions;
- policy, process, system, training, and supervision changes; and
- testing to determine whether remediation works.
8. Third-Party Compliance
Risk-based third-party controls may include:
☐ Business rationale and service description
☐ Ownership, qualifications, reputation, and government connections
☐ Compensation, payment terms, and bank-account review
☐ Risk-based due diligence and approvals
☐ Contractual compliance, audit, termination, and information rights
☐ Training and certifications
☐ Transaction monitoring and invoice support
☐ Periodic refresh and offboarding
Red flags must be resolved and documented; commercial urgency does not replace required review.
9. Mergers, Acquisitions, and Joint Ventures
The Company will define responsibility and timing for:
☐ Pre-acquisition risk assessment and due diligence
☐ Contract protections and disclosure schedules
☐ Day-one reporting and policy access
☐ Post-closing compliance integration
☐ Books, records, controls, data, and third-party remediation
☐ Follow-up testing and escalation of inherited issues
10. Incentives and Discipline
Compliance will be considered in relevant performance, promotion, compensation, and award processes to the extent permitted by applicable law and Company plans. Discipline will consider role, intent, impact, cooperation, prior history, supervisory responsibility, and consistency across comparable cases.
| Measure | Owner | Approval | Documentation location |
|---|---|---|---|
| Compliance performance criteria | [________________________________] | [________________________________] | [________________________________] |
| Recognition or incentive | [________________________________] | [________________________________] | [________________________________] |
| Discipline matrix | [________________________________] | [________________________________] | [________________________________] |
| Compensation reduction or recovery | [________________________________] | [________________________________] | [________________________________] |
11. Monitoring, Testing, Data, and Continuous Improvement
11.1 Monitoring Plan
| Risk or control | Data source | Test or metric | Frequency | Owner | Escalation threshold |
|---|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
11.2 Program Effectiveness
The Company will use appropriate data and qualitative evidence to assess whether policies are understood, controls operate, reports are investigated, remediation closes, discipline is consistent, and recurring issues decline.
11.3 Emerging Technology
The Company will assess compliance risks arising from artificial intelligence and other new technology, including intended use, data, access, human oversight, reliability, security, monitoring, accountability, and potential misuse.
12. Records and Communications
Each policy owner will identify the legal, regulatory, contractual, operational, and litigation-hold rules governing records in that domain. This Manual does not create a single universal retention period.
Business communications must use approved channels and settings. Policies for personal devices, bring-your-own-device programs, messaging applications, and ephemeral messaging will address access, preservation, security, privacy, and local-law limitations.
13. Conditional Federal Legal Overlays
13.1 FCPA Anti-Bribery
If 15 U.S.C. § 78dd-1 applies, an issuer and covered persons acting on its behalf may not corruptly use interstate commerce in furtherance of specified offers, payments, promises, or authorizations involving foreign officials, political parties, candidates, or intermediaries for the prohibited business purpose described in the statute. Counsel must assess the statute's elements, exceptions, defenses, and the other FCPA jurisdictional provisions before reaching a conclusion.
13.2 Issuer Books, Records, and Internal Accounting Controls
If 15 U.S.C. § 78m(b)(2) applies, the issuer must keep books, records, and accounts that accurately and fairly reflect transactions and asset dispositions in reasonable detail and maintain the internal accounting controls described in the statute.
13.3 Securities Whistleblowers
If 18 U.S.C. § 1514A applies, the Company's procedures must preserve the activities and remedies protected by that section. Separately, 17 C.F.R. § 240.21F-17 prohibits action that impedes direct communications with SEC staff about a possible securities-law violation.
14. State, Local, Industry, and International Riders
Do not use one-line generic state claims. Create a rider only after confirming current official authority and actual applicability.
| Jurisdiction or regulator | Topic | Official authority | Owner | Required control or procedure | Last verified |
|---|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [__/__/____] |
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [__/__/____] |
15. Exceptions, Review, and Approval
15.1 Exceptions
Policy exceptions require documented risk analysis, approval by the designated authority, compensating controls, and an expiration or review date.
15.2 Review Checklist
☐ Risk assessment is current and tied to resources
☐ Policies reflect current official law and operational practice
☐ Training is risk-based and measured for effectiveness
☐ Reporting channels are accessible and tested
☐ Investigations are independent, timely, and documented
☐ Third-party and M&A controls operate in practice
☐ Incentives and discipline are applied consistently
☐ Data, testing, and lessons learned drive improvements
☐ Emerging technology and messaging risks are addressed
☐ State, local, industry, and international riders are current
15.3 Approval
| Role | Name | Approval or signature | Date |
|---|---|---|---|
| Document owner | [________________________________] | [________________________________] | [__/__/____] |
| Chief compliance officer | [________________________________] | [________________________________] | [__/__/____] |
| General counsel or legal reviewer | [________________________________] | [________________________________] | [__/__/____] |
| Board or committee chair | [________________________________] | [________________________________] | [__/__/____] |
Employee Acknowledgment
I acknowledge receipt of this Manual and understand where to seek advice and report concerns. This acknowledgment does not waive any right to communicate with a government agency or engage in activity protected by applicable law.
Name: [________________________________]
Signature: [________________________________]
Date: [__/__/____]
Sources and References
- U.S. Department of Justice, Evaluation of Corporate Compliance Programs (updated September 2024): https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl
- GovInfo, 15 U.S.C. § 78dd-1: https://www.govinfo.gov/app/details/USCODE-2024-title15/USCODE-2024-title15-chap2B-sec78dd-1
- GovInfo, 15 U.S.C. § 78m: https://www.govinfo.gov/app/details/USCODE-2024-title15/USCODE-2024-title15-chap2B-sec78m
- GovInfo, 18 U.S.C. § 1514A: https://www.govinfo.gov/app/details/USCODE-2024-title18/USCODE-2024-title18-partI-chap73-sec1514A
- eCFR, 17 C.F.R. § 240.21F-17: https://www.ecfr.gov/current/title-17/part-240/section-240.21F-17
About This Template
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Important Notice
This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Last updated: July 2026
Get your Corporate Compliance Manual - New York, done and ready to use
Fill it in for your situation, adjust it for your state, and download the finished Word and PDF. Let the AI do it in about 5 minutes, or finish it yourself in the editor. $99 one time, or go Pro for access to every document and every Ezel app.