Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Compliance Strategy

The First 90 Days as a New Compliance Officer: Inventory Before You Rewrite

A compliance checklist template for your first 90 days: inventory obligations, issues, complaints, commitments, controls, access, and evidence first.

Table of Contents

TL;DR

  • Your first deliverable is not a new policy suite. It is a verified map of obligations, commitments, products, controls, gaps, owners, and evidence.
  • Work in this order: preserve and triage in days 1–30, validate how the program operates in days 31–60, then commit to a realistic build plan in days 61–90.
  • Keep a “management says” column separate from “evidence confirms.” That distinction will save you during the first exam or bank-partner review.

The fastest way to lose your first 90 days is to start rewriting the compliance manual on day three.

You were just hired with nothing—or, more accurately, with six SharePoint sites, an expired calendar, a complaint tracker nobody owns, and a confident assurance that “the last compliance person handled that.”

A useful compliance checklist template starts with inventory, not prose. Before changing what the program says, establish what the company does, what it owes, what has already gone wrong, and what evidence exists.

That sequence matches how examiners think. The OCC’s Compliance Management Systems Comptroller’s Handbook defines a CMS as policies, procedures, processes, monitoring and testing, and compliance audit. Its examiner framework covers board and management oversight, change management, risk identification, corrective action, policies and procedures, training, monitoring and audit, and complaint response. A new binder addresses only one slice.

Days 1–5: secure the record before diagnosing it

The first week is evidence preservation and access recovery.

Ask for administrator or read access—not emailed screenshots—to the systems that hold:

  • contracts and bank-partner agreements;
  • regulator, licensing, and examination correspondence;
  • complaint and dispute records;
  • issue, audit, and remediation trackers;
  • policy and procedure repositories;
  • regulatory change alerts and implementation records;
  • learning-management and training records;
  • product, marketing, and change-approval tickets;
  • vendor inventory and diligence files;
  • transaction monitoring, case management, and quality-assurance tools;
  • board and compliance committee materials;
  • customer communications and disclosure versions.

Record access requests and limitations. “Compliance could not independently retrieve complaint data and relied on monthly Operations exports” is itself a governance fact. Do not hide it in your personal notes.

Preserve the old record before reorganizing. Bulk-moving files into your preferred folder structure can break links from issue trackers, destroy version context, or make historical approvals hard to reconstruct. Take a repository inventory, identify systems of record, and establish retention before cleanup.

Build a source-of-truth register

DomainSystem of recordOwnerCoverage datesAccessKnown limitationNext verification
Consumer complaintsSupport platformVP SupportJan. 2025–presentRead onlySocial-media complaints excludedReconcile channels to complaint policy
Bank-partner commitmentsContract repositoryGeneral CounselActive agreementsPendingSide letters stored in emailLegal certification and sample
Compliance issuesShared workbookHead of ComplianceMixedFullClosure evidence not linkedSample all High/Critical closures
TrainingLMSPeople Ops2024–presentAdminContractor population unclearReconcile HR roster to assignments

The entries are illustrative. The method is the point: distinguish the location of information from confidence that it is complete.

Days 1–30: inventory obligations and live exposure

The CFPB’s Compliance Management Review Examination Procedures says a CMS should be integrated across product design, delivery, and administration; issues should be self-identified; corrective action should be initiated; and service providers should be overseen. Use those operating pathways to structure discovery.

1. Obligations and deadlines

Create one obligation register that identifies:

  • law, regulation, license, order, contract, network rule, or policy source;
  • specific requirement and citation;
  • entity, product, state, customer, and activity in scope;
  • control and evidence expected;
  • business and compliance owners;
  • filing, review, reporting, or renewal date;
  • current status and verification source.

Do not confuse a regulatory library with an applicability decision. A folder containing the Equal Credit Opportunity Act does not establish which products invoke which requirements, where controls operate, or whether your company is the creditor, service provider, or program manager.

Start with deadlines that can hurt immediately: license renewals, regulatory responses, bank-partner deliverables, required filings, remediation commitments, customer-notice obligations, and open examination requests.

2. Commitments somebody already made

Commitments hide in places a policy inventory misses:

  • consent orders and examination responses;
  • MRA or MRIA remediation plans;
  • bank-partner oversight letters;
  • audit management responses;
  • board-approved corrective actions;
  • customer remediation promises;
  • contract schedules and side letters;
  • responses to due-diligence questionnaires;
  • statements in prior regulatory applications.

Build a commitments ledger with exact language, date, recipient, owner, deadline, status, and evidence. A promise to “implement quarterly monitoring” is an obligation even if nobody added it to the compliance calendar.

3. Open issues—and suspiciously closed ones

Collect findings from regulatory exams, internal audit, compliance testing, risk assessments, complaints, incidents, vendor reviews, and self-identification.

For every High or Critical item, check:

  • original finding and source;
  • root cause;
  • remediation action and accountable owner;
  • approved due date and extensions;
  • closure evidence;
  • independent validation;
  • recurrence or related complaints;
  • residual risk acceptance.

Do not accept “closed” as a fact without evidence. The issue closure guide separates action completion from verified risk reduction—exactly the distinction an inherited tracker tends to blur.

4. Complaints, disputes, and customer remediation

Complaint data tells you where the program is failing in production. Reconcile all intake channels: support, email, phone, chat, app stores, social media, CFPB portal, bank partners, Better Business Bureau, and legal escalations where applicable.

The Federal Reserve’s Consumer Compliance Outlook article “Enhancing the Compliance Management Program with Complaint Data” explains how complaint analysis can identify compliance risks and support program enhancement. Do not stop at volume. Review themes, severity, products, channels, root causes, refunds, reopened complaints, regulatory allegations, and repeat customers.

A practical first-month artifact is a top-ten complaint sample: five recent escalations and five high-impact or repeat cases. Trace each from intake to investigation, response, remediation, root cause, and control change.

5. Products, money movement, and customer journeys

Policies are organized by topic. Harm happens through workflows.

For each active product, map:

  • legal entities and licenses;
  • sponsor banks, processors, and critical vendors;
  • customer segments and jurisdictions;
  • application, onboarding, decision, servicing, complaint, and exit steps;
  • fees, disclosures, marketing claims, and customer communications;
  • movement and custody of funds;
  • manual overrides and operational queues;
  • regulatory control owners;
  • planned product or configuration changes.

Ask Product to show the live journey. Ask Operations to show the exceptions. Ask Engineering to show configurations. The documented process and the working process are often cousins, not twins.

By day 30: deliver a triage memo, not a transformation deck

Classify findings into four lanes:

LaneDecision testExample response
Contain nowActive harm, likely legal breach, unauthorized activity, or missing critical controlPause feature, restrict access, correct disclosure, escalate to counsel
Deadline-boundRegulatory, licensing, contractual, exam, or board commitment is approachingNamed owner, daily tracking, evidence plan
Validate quicklyMaterial risk exists but facts or control operation are uncertainTargeted sample, walkthrough, configuration review
RoadmapDocumentation debt or program enhancement without immediate exposurePrioritized 60–90 day design work

A triage memo should state verified facts, assumptions, unknowns, interim controls, required decisions, and owners. Avoid calling every inherited weakness “critical.” If everything is urgent, leadership cannot tell what must happen Monday.

Days 31–60: test whether the program actually operates

Now move from inventory to validation.

Walk one obligation through the whole chain

Choose a high-risk obligation and trace:

Source → applicability → policy → procedure → system configuration → training → monitoring → issue handling → management reporting.

For example, take one fee disclosure. Verify the legal requirement, approved disclosure, product configuration, customer presentation, change history, quality-assurance test, complaint trend, and reporting. This single-chain test exposes handoff failures faster than reading 40 policies independently.

The regulatory change implementation record provides the same proof chain for new rules: applicability, implementation, configuration, training, testing, effective date, and residual gaps.

Inventory undocumented controls

Some of the strongest controls may exist only because a tenured Operations analyst remembers to run them. Capture:

  • trigger and population;
  • activity performed;
  • system and data used;
  • frequency;
  • owner and backup;
  • evidence retained;
  • reviewer or escalation;
  • known exceptions;
  • dependency on one person.

Do not immediately write these into policy as permanent design. First determine whether the control is required, reliable, scalable, and correctly owned. A heroic spreadsheet reconciliation may be the only thing preventing harm—and also a control that fails during one employee’s vacation.

Compare representations with evidence

Use three status labels:

  • Verified: direct evidence supports the conclusion.
  • Represented: an owner stated it, but evidence is pending.
  • Contradicted: evidence conflicts with the stated process.

Example:

StatementStatusEvidence
“All marketing is reviewed by Compliance”ContradictedThree live campaigns have no approval ticket
“Critical vendors are reviewed annually”RepresentedCalendar supplied; completed reviews not yet sampled
“Refund overrides require dual approval”VerifiedConfiguration plus 25-item sample shows two approvers

This is not a “gotcha” register. It prevents a verbal walkthrough from becoming an unsupported assurance to the board, examiner, or bank partner.

Days 61–90: decide what to rebuild, repair, or retire

Only now should large-scale rewriting begin.

Rewrite in control order

Prioritize documents where:

  • the operating process materially differs from policy;
  • obligations or products changed;
  • ownership is wrong or vacant;
  • the current policy creates repeated exceptions;
  • procedures cannot be tested;
  • an issue, complaint trend, or exam commitment requires change.

For each revision, identify the implementation owner, system or procedure change, training population, effective date, monitoring test, and evidence. Policy approval without operating change is document production, not remediation.

Build a 12-month plan with capacity attached

A credible roadmap includes:

Work itemRisk addressedDeliverableOwnerDependencyDecision dateValidation
Complaint taxonomy repairRepeat issues are not visible across channelsUnified taxonomy and channel mappingCompliance + SupportData export changesDay 75Sample 50 cases across channels
Commitment ledgerBank-partner deliverables may be missedCentral register with remindersCompliance + LegalContract inventoryDay 60Reconcile active agreements
Monitoring planControls lack second-line testingRisk-based test universe and calendarCompliance TestingObligation/control mapDay 90Committee approval and first test

Sample sizes and dates are illustrative. Calibrate testing to population, harm, history, and resources, and reconcile samples to source-system populations so convenient records cannot be selected.

Ask management for decisions, not applause

Your day-90 report should show:

  • verified program map;
  • urgent exposures contained;
  • overdue and upcoming obligations;
  • issue and commitment inventory;
  • evidence and ownership gaps;
  • products and third parties requiring deeper review;
  • resources and access needed;
  • decisions that exceed your authority;
  • sequenced roadmap with validation.

The OCC handbook says boards should receive risk assessments, monitoring, and independent audit information sufficient to assess CMS effectiveness and provide credible challenge. Give leadership the information needed to decide—not 40 green status boxes.

What not to do in the first 90 days

Do not delete the old evidence trail. Preserve versions, approvals, and actual dates.

Do not promise a clean program before inventory is complete. Report confidence and unknowns.

Do not let the loudest stakeholder set the priority list. Rank by harm, obligation, deadline, and control dependency.

Do not own every control. Compliance should govern and challenge; business, Operations, Product, Engineering, and vendor owners must operate many controls.

Do not make the policy more mature than operations. A strict new requirement with no system, staffing, or owner creates instant noncompliance.

Do not spend 90 days diagnosing without containment. Inventory first does not mean wait to act on active harm or an imminent missed obligation.

So What?

Your first-week task is simple: build the source-of-truth register and the commitments ledger. Your first-month task is harder: identify which inherited statements are verified, represented, or contradicted. Your day-90 task is to leave management with a prioritized, owned, fundable plan.

The best signal that the takeover worked is not a prettier manual. It is that you can answer, with evidence: what do we owe, where does the control operate, who owns it, what is broken, what are we doing, and who accepted anything left open?

The GRC Starter Kit bundles the foundational registers, risk, issue, vendor, and AI-governance templates a new compliance hire needs to turn that inventory into an operating program.

Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What should a new compliance officer do in the first 30 days?
Preserve evidence, confirm authority and system access, inventory legal and contractual obligations, collect open issues and commitments, map complaints and regulatory requests, identify critical third parties, and document urgent exposure. Avoid rewriting policies until you know which obligations, products, controls, owners, and exceptions the current documents are supposed to govern.
Which compliance documents should be inventoried first?
Start with regulator and bank-partner commitments, licenses and filings, open findings, complaints, risk assessments, monitoring and testing results, policies and procedures, training records, vendor oversight, product approvals, exceptions, committee minutes, and evidence repositories. Prioritize by deadline, consumer harm, legal obligation, and operating criticality.
Should a new compliance officer immediately rewrite outdated policies?
Usually not. First compare policy requirements with current products, systems, owners, procedures, and control evidence. A fast rewrite can erase useful history, create requirements operations cannot meet, or hide a known deviation. Stabilize urgent gaps, then revise documents through controlled change with named implementation and testing owners.
How should a solo compliance officer prioritize inherited gaps?
Use consequence and time sensitivity: active consumer harm or legal breach first; imminent regulatory, licensing, contractual, or exam commitments next; critical control failures and unsupported high-risk products after that; then documentation debt. Record why lower-priority work was deferred and what interim monitoring is in place.
What should the first 90-day compliance report include?
Report the verified obligation inventory, current program map, urgent exposures contained, open findings and commitments, control-evidence gaps, ownership gaps, third-party dependencies, access limitations, decisions needed from management, and a funded remediation roadmap. Separate confirmed facts from unverified management representations.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

GRC Starter Kit

Everything a new compliance hire needs to build their first risk program — 6 products at 46% off.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.