Research Note
Corporate Compliance Source Record Framework
A compliance source record should allow an authorized reviewer to reconstruct what question was asked, which facts were considered, which authorities controlled, who inte
In this article
Corporate Compliance Source Record Framework
Purpose
A compliance source record should allow an authorized reviewer to reconstruct what question was asked, which facts were considered, which authorities controlled, who interpreted them, what decision was made, where operational evidence lives, and what will trigger a refresh.
It should not become a casual warehouse for identity documents, beneficial-owner data, credentials, account numbers, or privileged legal analysis.
Minimum record
The record needs a stable internal entity identifier, formation jurisdiction or other scope fact, the exact compliance question, the triggering event, the as-of date, controlling authorities, explanatory sources, later actions checked, interpretation owner, adviser reference, decision state, approval, evidence location, retention class, refresh date, and event-based refresh triggers.
The source entry should preserve title, issuing body, URL or citation, publication date, effective date, accessed date, relevant section, version or hash when appropriate, and whether a later authority superseded it.
Separation
An ordinary Obsidian note can store public authorities, non-sensitive scope facts, workflow state, and links into approved systems. Restricted systems should store personal identifiers, identity images, filings, receipts containing protected data, and privileged or confidential advice according to organizational policy.
The public guide offers a sanitized Markdown structure. Organizations must adapt it to legal hold, retention, records-management, security, privacy, and privilege requirements.
History
Do not overwrite an old legal state. Mark it superseded, link the new authority, and record when the decision changed. The E048 package demonstrates why: the December 2024 answer, February 2025 posture, March 2025 enforcement announcement, and March 2025 rule were distinct states.
Review states
Useful states are research in progress, counsel review, approved to act, approved not to act, held for change, superseded, and closed with a continuing refresh trigger.
Boundary
The framework is not a substitute for counsel, a document-management policy, a privacy program, or a security design. It should be adopted only after those owners review it.
Sources
Follow the evidence.
- fincen.gov: boifincen.gov
- fincen.gov: newsroomfincen.gov
- home.treasury.gov: 2026 NMLRAhome.treasury.gov
- youtu.be: fqyzSjGbUloyoutu.be
- justice.gov: td bank pleads guilty bank secrecy act and money laundering conspiracy violations 18bjustice.gov
- federalregister.gov: beneficial ownership information reporting requirement revision and deadline extensionfederalregister.gov
- fincen.gov: fincen assesses record 13 billion penalty against td bankfincen.gov
- federalregister.gov: beneficial ownership information reporting requirementsfederalregister.gov
- ecfr.gov: section 1010ecfr.gov
- congress.gov: PLAW 116publ283congress.gov
- occ.treas.gov: nr occ 2024 116occ.treas.gov
- daltonanderson.ghost.io: boi filing cta what founders need to know nowdaltonanderson.ghost.io
- open.spotify.com: 4q4989dGjvhcgax9VgaN2fopen.spotify.com
- fincen.gov: fincen removes beneficial ownership reporting requirements us companies and usfincen.gov
- federalreserve.gov: enforcement20241010afederalreserve.gov
- fincen.gov: FinCEN Order CCDExceptiveRelieffincen.gov
- fincen.gov: BOI FAQs QA 508Cfincen.gov
- fincen.gov: cdd rule faqsfincen.gov