Research Note

Corporate Compliance Source Record Framework

A compliance source record should allow an authorized reviewer to reconstruct what question was asked, which facts were considered, which authorities controlled, who inte

Aug 4, 20262 min readBy Dalton Anderson
In this article

Corporate Compliance Source Record Framework

Purpose

A compliance source record should allow an authorized reviewer to reconstruct what question was asked, which facts were considered, which authorities controlled, who interpreted them, what decision was made, where operational evidence lives, and what will trigger a refresh.

It should not become a casual warehouse for identity documents, beneficial-owner data, credentials, account numbers, or privileged legal analysis.

Minimum record

The record needs a stable internal entity identifier, formation jurisdiction or other scope fact, the exact compliance question, the triggering event, the as-of date, controlling authorities, explanatory sources, later actions checked, interpretation owner, adviser reference, decision state, approval, evidence location, retention class, refresh date, and event-based refresh triggers.

The source entry should preserve title, issuing body, URL or citation, publication date, effective date, accessed date, relevant section, version or hash when appropriate, and whether a later authority superseded it.

Separation

An ordinary Obsidian note can store public authorities, non-sensitive scope facts, workflow state, and links into approved systems. Restricted systems should store personal identifiers, identity images, filings, receipts containing protected data, and privileged or confidential advice according to organizational policy.

The public guide offers a sanitized Markdown structure. Organizations must adapt it to legal hold, retention, records-management, security, privacy, and privilege requirements.

History

Do not overwrite an old legal state. Mark it superseded, link the new authority, and record when the decision changed. The E048 package demonstrates why: the December 2024 answer, February 2025 posture, March 2025 enforcement announcement, and March 2025 rule were distinct states.

Review states

Useful states are research in progress, counsel review, approved to act, approved not to act, held for change, superseded, and closed with a continuing refresh trigger.

Boundary

The framework is not a substitute for counsel, a document-management policy, a privacy program, or a security design. It should be adopted only after those owners review it.

Sources

Follow the evidence.

  1. fincen.gov: boifincen.gov
  2. fincen.gov: newsroomfincen.gov
  3. home.treasury.gov: 2026 NMLRAhome.treasury.gov
  4. youtu.be: fqyzSjGbUloyoutu.be
  5. justice.gov: td bank pleads guilty bank secrecy act and money laundering conspiracy violations 18bjustice.gov
  6. federalregister.gov: beneficial ownership information reporting requirement revision and deadline extensionfederalregister.gov
  7. fincen.gov: fincen assesses record 13 billion penalty against td bankfincen.gov
  8. federalregister.gov: beneficial ownership information reporting requirementsfederalregister.gov
  9. ecfr.gov: section 1010ecfr.gov
  10. congress.gov: PLAW 116publ283congress.gov
  11. occ.treas.gov: nr occ 2024 116occ.treas.gov
  12. daltonanderson.ghost.io: boi filing cta what founders need to know nowdaltonanderson.ghost.io
  13. open.spotify.com: 4q4989dGjvhcgax9VgaN2fopen.spotify.com
  14. fincen.gov: fincen removes beneficial ownership reporting requirements us companies and usfincen.gov
  15. federalreserve.gov: enforcement20241010afederalreserve.gov
  16. fincen.gov: FinCEN Order CCDExceptiveRelieffincen.gov
  17. fincen.gov: BOI FAQs QA 508Cfincen.gov
  18. fincen.gov: cdd rule faqsfincen.gov

From this episode

Two useful next steps.

Evergreen · 1 min

How to Verify a Federal Filing Requirement Before Acting

Build a dated trail from entity facts to the statute, current rule, agency guidance, court status, deadline, and accountable filing decision.

Research Note · 1 min

Ownership Transparency and AML Control Map Record

Corporate BOI reporting, bank customer due diligence, transaction monitoring, alert investigation, suspicious activity reporting, sanctions screening, governance, and enf

Return to the episode