Skip to content.
Two men in business attire have a conversation across a table in a modern office setting, separated by a glass partition. One man gestures with his hands while speaking, while the other listens attentively with his back to the camera.

You asked, we’re answering

Conflict of interest disclosures may look straightforward on paper, but in practice, the situations employees and compliance teams encounter are rarely simple. 

This much was clear from the questions we received during our recent NAVEX webinar , 5 Conflict of Interest Myths Debunked. We explored what nearly 200,000 employee disclosures reveal about conflict of interest risk – including why relationships are the most common disclosure category, how risks differ by employee role and region and why disclosure programs need to evolve over time. 

The conversation also raised practical questions that the data alone cannot answer. When should an employee disclose a personal relationship? How should organizations approach conflicts involving executives or board members? What happens when third parties are involved? And how can compliance teams design policies and processes that account for situations where the right answer depends on context? 

We weren’t able to address every question during the session, so we’ve brought together some of the most thought-provoking questions here. While specific requirements will depend on your organization’s policies, applicable laws and individual circumstances, these considerations can help compliance teams think through how they approach common – and sometimes complicated – conflict of interest scenarios.

Relationships – the most common disclosure type and most nuanced category

Could you mention types of personal relationships that directors or specific employees would be required to disclose? Thinking that not every employee of a company who has a romantic relationship with the employee of a competitor company is supposed to disclose this relationship? 

Not every personal or romantic relationship needs to be disclosed – only those where there is an actual, potential or perceived conflict of interest. Employees should disclose a personal relationship where it could reasonably affect, or appear to affect, their objectivity or decision-making at work. This could include romantic or intimate relationships, including spouses and partners; immediate or close family relationships, such as parents, children, siblings or other close relatives; and close personal friendships where the relationship could influence, or appear to influence, business decisions. 

These relationships would generally need to be disclosed when the other person has a relevant business connection – for example, a colleague in the reporting line, director, key client, supplier or competitor – and an actual, potential or perceived conflict could arise. A relationship with an employee of a competitor would not automatically require disclosure unless there is a particular conflict or confidentiality risk. Other examples include situations where the individual is involved in recruitment, pay or promotion decisions, or has access to relevant confidential or commercially sensitive information. 

The policy should focus on the risks posed by the relationship rather than unnecessarily requiring employees to disclose private relationships. Employees also should not be expected to determine whether a conflict actually exists. The disclosure obligation should cover situations that could create (or appear to create) a conflict, allowing the organization to assess the facts and determine whether safeguards are needed. Framing disclosure as a request for guidance rather than an admission of wrongdoing can also encourage employees to raise questions early. If employees are unsure whether a relationship creates a conflict, they should have a clear, confidential way to seek guidance. 

For nepotism/relationship questions, how do you typically word them? Would it be reasonable to also ask who resides in the individual’s household to ensure all relevant relationships are disclosed and avoid potential gaps?

Avoid asking employees to list everyone in their household. A more proportionate approach is to focus on relationships that could create a conflict. For personal relationships, organizations might ask: “Do you have any close personal, family, romantic or household relationship that creates, or could reasonably be perceived to create, a conflict of interest in connection with your role?”

For nepotism, the question could be more specific: “Do you have a close personal or family relationship with any employee, director, contractor or applicant where you have, or may have, influence over their recruitment, remuneration, promotion, performance or other employment decisions?”

It can also be reasonable to include people residing in the same household within the definition of relevant relationships rather than asking employees to provide a list of everyone who lives there. For example, “close personal relationship” could include a spouse or partner, an immediate family member, a person living in the same household or another relationship sufficiently close to create an actual, potential or perceived conflict. 

Is the relationship with co-worker disclosure implemented often in school systems?  

Policies and practices can vary significantly across school systems. A risk-based approach applies the same test used in other workplaces: require disclosure when a relationship could affect hiring, supervision, evaluation, pay, scheduling, promotion or another work decision rather than requiring disclosure of every relationship between coworkers. 

What about chasing disclosures from the other relevant partner when only one discloses the relationship? 

If both people are employees, the organization should generally follow up with the employee who did not disclose. The follow-up can confirm the facts and support appropriate safeguards, but it is also an opportunity to explain why disclosure was required and reinforce the organization’s expectations. The organization should document the follow-up and management plan, including informing appropriate managers or others responsible for implementing and monitoring safeguards. Whether a second disclosure form is necessary may depend on the organization’s process, but both employees should understand their responsibilities and report any material change.

In small communities, a risk-based rather than relationship-based approach is more practical. Simply knowing someone, being distantly related or having a community connection should not automatically require disclosure. Disclosure should be required where the relationship is sufficiently close that it could influence, or reasonably appear to influence, a work-related decision, particularly in situations involving recruitment, supervision, pay, promotion, procurement, contracting or other financial or business decisions. 

Policies can recognize that connections are common in small communities and that the existence of a relationship is not itself a conflict. A useful test is: “Could a reasonable person question my impartiality because of this relationship?” If the answer is yes, disclose it and allow the organization to determine whether safeguards are needed. 

When employees start a romantic relationship, at which point would they be required to disclose?

Rather than setting a fixed timeframe, such as one or three months, disclosure should be required once the relationship becomes relevant from a conflict-of-interest perspective. For example, disclosure should be prompt where there is a reporting relationship, decision-making authority or potential impact on recruitment, pay, promotion, performance or other employment matters. A very new or casual relationship with no workplace conflict would not necessarily need to be disclosed. 

If a disclosed relationship ends, employees should inform HR of any original conflict or safeguards that may be affected so any arrangements can be reviewed. The policy could simply state that employees must disclose a relevant relationship “as soon as reasonably practicable” and notify HR of any material change in circumstances.

Board and executive conflicts

From a theoretical perspective and level of risk arising from a potential COI, would an executive most likely result in a higher level of risk?

From a theoretical COI risk perspective, an executive would typically present a higher potential risk, although seniority alone should not determine the assessment. Executives generally have greater decision-making authority, influence and access to confidential or commercially sensitive information. Their relationships may therefore create greater actual, potential or perceived conflicts, and the potential impact may be higher because their decisions can affect strategy, people, suppliers, clients, investments or financial matters. 

It can therefore be reasonable to apply more comprehensive disclosure expectations to directors and executives while using a more targeted, role-based approach for other employees. Ultimately, risk should be assessed based on seniority, the nature of the relationship, decision-making influence and access to sensitive information rather than job title alone. Executive conflicts should also be reviewed independently where feasible. Depending on the circumstances, that may mean review by the chief compliance officer, general counsel or an appropriate board committee rather than someone in the executive’s reporting line. 

Most firms have mature controls around gifts, hospitality and personal conflicts. In your experience, what does good practice look like for identifying and managing strategic conflicts of interest where executive remuneration, shareholder expectations and growth targets may consciously or unconsciously influence decision-making, particularly in regulated financial services firms?

Situations where executive remuneration, shareholder expectations and growth targets influence decision-making – particularly in regulated financial services firms – can be understood as structural incentive risks as well as conflicts of interest. Financial services regulators have recognized these risks, including the possibility that remuneration and performance-management arrangements may encourage excessive risk-taking, misconduct or poor customer outcomes. Good practice includes independent board or committee oversight of compensation and performance targets, balanced measures that account for conduct and risk, meaningful authority for risk and compliance functions and monitoring for signs that business pressure is distorting decisions. 

What is your recommendation regarding the conflict-of-interest risk of onboarding a former executive (e.g., someone who has retired) as a supplier?

A former executive becoming a supplier is not inherently problematic, but it should be treated as a heightened COI scenario that warrants additional scrutiny, particularly soon after the executive leaves. Before onboarding, conduct and document a COI assessment considering the individual’s former seniority, influence, access to confidential information and relationships with current decision-makers. The former executive should have no involvement in, or undue influence over, supplier selection or commercial terms, and current executives with close relationships should disclose them and recuse themselves where appropriate. 

The organization should apply its normal procurement and due diligence process, ideally documenting that pricing and terms are commercially reasonable and comparable to alternatives. It should also check relevant post-employment restrictions, cooling-off requirements or regulatory obligations and consider whether the arrangement could create a reasonable perception of preferential treatment even without an actual conflict. The rationale for appointment and any mitigating controls should be documented, with enhanced approval for higher-risk cases. Unless a regulatory or contractual requirement dictates otherwise, a risk-based assessment with independent approval may be more proportionate than a blanket prohibition or fixed cooling-off period.

Third-party disclosures

The principal value of data matching is to identify relationships or interests that may not have been disclosed. Where legally permissible, organizations might compare employee addresses or other appropriate identifiers against vendor records, or search public corporate-registration and ownership records for businesses associated with employees. Disclosed information may also be used to validate or clarify details when necessary. 

Any match should be treated as a lead for human review, not proof of a relationship or conflict. The process should also include appropriate privacy, access and data-retention safeguards. 

Miscellaneous disclosure questions

How would you handle COI disclosures that indicate there’s an NDA in place so no further information can be shared with the employer?

An NDA should not automatically prevent further assessment. A practical approach is to acknowledge the NDA while establishing what information can legally be disclosed without breaching it. Ask for the minimum information necessary to assess the conflict – for example, the nature or category of the interest, the parties involved where permissible and how the interest could intersect with the employee’s role. 

Where details genuinely cannot be shared, involve Legal or Compliance and consider whether information can be provided on a restricted, need-to-know basis. If sufficient information still cannot be obtained, the lack of transparency can itself be considered a risk factor and proportionate controls may be appropriate, such as recusal, restricted access or removal from relevant decisions. Document both the disclosure and why the organization could or could not adequately assess the COI. An NDA should protect confidential information, but it should not become a mechanism for avoiding appropriate COI oversight. 

How would you change the perspective that COI and culture are not important enough for E&C resources during budget cuts?

COI and culture work should be framed as preventive risk controls rather than optional “soft” E&C activities. Weak COI management can contribute to procurement issues, favoritism, regulatory breaches, fraud, poor decision-making and reputational damage. Culture also plays a critical role in whether employees actually disclose and escalate issues. When resources are constrained, the response should be risk-based prioritization, not removing these controls altogether. 

Failing to address a COI policy violation does more than leave that particular conflict unmanaged. It can signal that policies may not be enforced consistently, especially when the person involved is senior or influential. Once employees perceive that enforcement is selective, they may be less likely to disclose concerns and more likely to conclude that other rules are also negotiable. In this way, the way an organization responds to individual conflicts can have broader implications for its speak-up culture and compliance program. 

NAVEX State of Risk & Compliance data reinforces this concern. Respondents who said leaders tolerated greater compliance risk also reported adverse outcomes of all types – including data or privacy breaches, adverse media, employee litigation and regulatory action – roughly 1.6 to two times as often. The data is correlational, but it supports the broader point: what leaders tolerate in one area can affect behavior across the organization. 

When budgets are tight, organizations can prioritize the highest-risk populations and decisions while continuing to enforce their policies consistently. Reducing resources may require difficult choices, but allowing COI controls or enforcement to fall away can create consequences that extend well beyond the individual conflict. 

What is the difference between conflict of interest and disclosure of interest? 

There is a useful distinction between the two. A disclosure of interest (DOI) is broader – it asks an individual to disclose relevant interests or relationships even if they do not currently constitute a conflict. A conflict of interest exists where an interest actually, potentially or apparently conflicts with the person’s responsibilities. 

In practice, “disclosure of interests” can be an effective way to frame the collection process. Employees disclose relevant interests, then the organization assesses whether those interests create an actual, potential or perceived conflict and determines whether mitigation is required. This approach also avoids placing the burden on employees to decide for themselves whether something technically constitutes a conflict. 

Should a company have a business code of conduct and a conflict of interest policy, or merge both?

A code of conduct and COI policy are closely linked but serve different purposes, so there is value in having both. The code of conduct should establish high-level principles and expected behaviors, including a clear requirement to identify, disclose and manage conflicts. The COI policy can then provide the detailed requirements – what constitutes a COI, examples, who must disclose, when and how to disclose, approval and escalation processes, registers, recusals and other controls. 

The code should cross-reference the COI policy rather than duplicate it. A simple way to distinguish their roles is: the code explains what the organization expects; the COI policy explains how conflicts are identified, disclosed and managed. 

What about personal account dealing?

Assuming this question refers to employees trading securities for their own accounts, personal account dealing is broader than insider trading and is usually addressed through dedicated controls, depending on the organization and applicable law.

Three people sit together at a table, looking at a laptop screen and discussing something. The setting appears to be a modern office with glass walls and bright lighting.

From individual disclosures to a clearer view of risk

If there is one theme connecting these questions, it is that effective conflict of interest management requires both structure and judgment. Policies can establish expectations, training can help employees recognize potential conflicts and disclosure processes can provide a consistent way to bring those situations forward. But organizations also need the flexibility to evaluate the facts and determine an appropriate response. 

That makes visibility especially important. A single disclosure may require a specific decision, but disclosure data viewed collectively can reveal recurring relationships, changing workforce risks, regional differences and areas where employees may need clearer guidance. 

The goal is to create a program in which employees know what may need to be disclosed, can easily find guidance and have a clear path to raise potential conflicts when they arise. For compliance teams, connecting those activities through NAVEX One can provide a more complete view of risk – bringing together policy guidance, education, disclosure management and program data to support more informed decisions. 

Conflict of interest risks will continue to evolve. The strongest disclosure programs are designed to evolve with them.