---
name: Corporate Compliance & ESG Program
description: Stand up a corporate compliance and risk program that actually runs — code of conduct, policies, controls, training, monitoring, whistleblower channels — plus ESG governance and disclosure discipline, so a company manages regulatory and reputational risk by design, with counsel owning the legal determinations.
audience: founder · ops/compliance lead · GC support · people ops
---

# Corporate Compliance & ESG Program

## What this is
A method for building the internal machinery that keeps a company on the right side of its obligations: a risk-based compliance program (policies, controls, training, monitoring, reporting) and an ESG governance layer with honest disclosure — designed to be effective, not decorative.

## What this is NOT
- **Not legal advice or a certification.** It designs the program; whether the company *is* compliant with a given law is counsel's call, and no framework here certifies compliance.
- **Not greenwashing.** ESG claims must be substantiated and consistent with what the company actually does; the skill flags unsupported or misleading sustainability claims (FTC Green Guides, emerging disclosure rules).
- **Not a substitute for a qualified compliance officer / GC** on regulated industries, investigations, or enforcement matters.

## When to use
Building a compliance program from scratch or maturing one; drafting a code of conduct or policy set; setting up training, monitoring, or a whistleblower channel; establishing ESG governance and preparing for disclosure; assessing program effectiveness before an audit or diligence.

## Operating principle
An effective program is risk-based and lived, not a binder. The DOJ's own test — is it well-designed, adequately resourced, and does it work in practice — drives the design: controls where the risk is, evidence that they run, and a speak-up culture that isn't punished.

## Capabilities
- **Program design** — Goal: a risk-based, defensible program. Method: risk assessment first, then policies/controls mapped to the top risks, role-based training, monitoring and testing, a whistleblower channel with anti-retaliation, and a documented governance structure (who owns what). Output: a program blueprint + a controls-to-risk map. Quality bar: controls trace to assessed risks; the program has evidence it operates, not just documents that it exists.
- **Policy & training** — Goal: clear, usable rules. Method: a code of conduct and targeted policies (anti-bribery, conflicts, data, third-party) in plain language, with training that changes behaviour and attestations that are tracked. Output: a policy set + training plan. Quality bar: policies are specific and enforceable; training is role-relevant, not one generic module.
- **ESG governance & disclosure** — Goal: honest, consistent ESG. Method: identify material ESG factors, assign governance/oversight, gather metrics with a data-quality note, and align public claims with reality; flag disclosure obligations (jurisdiction-dependent). Output: an ESG governance + disclosure-readiness note. Quality bar: every ESG claim is substantiated and consistent; unsupported or vague sustainability claims are flagged, not published.

## A worked example
"We want an ESG page saying we're carbon neutral." → The skill asks for the substantiation: scope 1/2/3 accounting, offsets quality, and third-party assurance. Without it, "carbon neutral" is flagged as a greenwashing/FTC risk; the recommendation is a governed, metric-backed disclosure of what's actually measured (labelled measured vs estimated), with the claim reviewed by counsel before it goes public.

## Guardrails & escalation
Whether the company complies with a specific law, any investigation, and enforcement response → qualified compliance counsel / GC. Regulated industries (financial, health, defense) → specialist compliance. ESG disclosure obligations and claims → legal + assurance. The skill builds the machine; counsel owns the legal calls.

## References
DOJ "Evaluation of Corporate Compliance Programs"; U.S. Sentencing Guidelines §8B2.1 (effective programs); FCPA and anti-bribery frameworks; ISO 37301 (compliance management); FTC Green Guides and emerging ESG-disclosure regimes (e.g., CSRD, SEC climate rules — confirm current status with counsel). Verify obligations for the jurisdiction and industry.
