Back to the episode map

Research Note

Product Compliance Review Framework

A product compliance review connects legal interpretation to the product that will actually ship. It is not a memo attachment, a generic checklist, or a claim that counse

Aug 4, 20262 min readBy Dalton Anderson

Product Compliance Review Framework

Purpose

A product compliance review connects legal interpretation to the product that will actually ship. It is not a memo attachment, a generic checklist, or a claim that counsel approved everything.

Review sequence

The team first freezes the proposed feature, markets, users, and timing. It then walks the working flow, including cohort rules, data inputs, failure states, alternate paths, administrator behavior, and what different observers can see.

The legal and domain owners identify applicable rules, licenses, contracts, guidance, and unsettled questions. The team records the facts supplied to each reviewer and preserves the version of each authority. Advice based on incomplete or later-changed facts must not travel as unconditional approval.

Risk analysis names the affected party, possible harm, likelihood, detectability, reversibility, and externalized cost. Each control receives an owner, test method, evidence, monitoring signal, and response path.

The decision record identifies the approver, material dissent, assumptions, boundaries, launch state, and automatic stop conditions. A material change to data, cohort logic, jurisdiction, purpose, or user experience triggers reapproval.

Required artifacts

ArtifactMinimum content
Working flowScreens, API behavior, flags, exceptions, and failure states
Data mapSource, purpose, access, retention, transfer, and deletion
Authority recordJurisdiction, rule, effective date, version, interpretation owner
Risk recordAffected party, harm, likelihood, detectability, reversibility
Control evidenceTest, result, owner, monitor, alert, and response
Decision recordScope, approver, dissent, assumptions, stop condition
Operating recordIncidents, complaints, changes, refreshes, and outcomes

DOJ alignment

The Justice Department's current materials ask whether a compliance program is well designed, adequately resourced and empowered, and working in practice. The framework borrows those governance questions. It does not claim that following the framework creates a legal safe harbor or predicts a prosecutor's decision.

Boundary

Counsel, privacy, security, records, regulatory, and domain owners must adapt the process to the organization and jurisdiction. Sensitive advice and personal data may require restricted systems rather than an ordinary project note.

Sources

Follow the evidence.

  1. daltonanderson.ghost.io: ubers greyball the dark side of tech innovationdaltonanderson.ghost.io
  2. whistleblowers.gov: complaint pagewhistleblowers.gov
  3. uber.com: an update on greyballinguber.com
  4. theguardian.com: uber used greyball fake app to evade police across europe leak revealstheguardian.com
  5. courthousenews.com: GREYBALL AUDIT REPORTcourthousenews.com
  6. justice.gov: jm 9 28000 principles federal prosecution business organizationsjustice.gov
  7. youtu.be: TiC4GmwZ nsyoutu.be
  8. sec.gov: whistleblower protectionssec.gov
  9. open.spotify.com: 32iYem7RXAQ2R7WyHdRrscopen.spotify.com
  10. justice.gov: dljustice.gov
  11. justice.gov: corporate enforcementjustice.gov
  12. whistleblowers.gov: faqwhistleblowers.gov
  13. NLRB protected concerted activitynlrb.gov
  14. portland.gov: statement mayor ted wheeler allegations uber used greyball tool sidestepportland.gov
  15. sec.gov: report possible securities law violationssec.gov
  16. ftc.gov: bringing dark patterns lightftc.gov
  17. justice.gov: criminal division announces publication guidance evaluating corporate compliance programsjustice.gov
  18. whistleblowers.govwhistleblowers.gov
  19. content.govdelivery.com: 198c3edcontent.govdelivery.com
  20. portland.gov: 631393portland.gov
  21. yahoo.com: exclusive uber faces criminal probe 083701705yahoo.com
Product Compliance Review Framework