1---2name: comprehensive-code-of-conduct-recently-public-biopharma3description: Comprehensive corporate code of conduct for a recently public biopharmaceutical company, incorporating industry-specific compliance requirements, healthcare-interaction controls, public-company disclosure and reporting practices, employee reporting protections, privacy and data-handling considerations, and an issues reconciliation memorandum documenting source conflicts and resolutions.4---56# Skill: Comprehensive Corporate Code of Conduct for Recently Public Biopharmaceutical Company78## 2. Failure modes the skill is correcting910- Drafting a generic ethics policy that omits biopharma-specific controls for healthcare interactions, transparency reporting, manufacturing quality, data integrity, and scientific recordkeeping11- Treating whistleblower protection as only an internal HR or hotline process, without expressly protecting reports to regulators, agencies, or other external authorities12- Combining clawback concepts without tying them to both the securities-law requirement and the applicable exchange-listing requirement, which leaves implementation incomplete13- Failing to address privacy, monitoring, cross-border data handling, and breach response for employee data and related operational records14- Writing a code that does not clearly state waiver, adoption, and review mechanics for a newly public company subject to exchange governance expectations15- Producing an issues memo that summarizes conflicts without identifying the conflict source, the adopted resolution, the rationale, and any open follow-up item16- Reaching conclusions without naming the governing statute, regulation, rule, or doctrine that supports the position1718## 3. Legal frameworks / domain conventions that apply1920- Healthcare-interaction compliance: federal anti-kickback principles, applicable program integrity rules, and industry guidance governing meals, consulting, speaker programs, educational support, grants, and transfers of value21- Transparency reporting: federal reporting rules for transfers of value and related data collection, validation, retention, and submission duties22- Manufacturing quality and data integrity: FDA manufacturing and quality-system requirements, including accurate records, deviation escalation, and prohibition on falsification or backdating23- Public-company governance: exchange-listing standards, board adoption expectations, periodic review obligations, and waiver handling for directors and executive officers24- Whistleblower and anti-retaliation protections: federal securities-law and other statutory protections for internal and external reporting, including protections for reports to government agencies without prior approval25- Clawback framework: securities-law compensation-recovery requirements and the related exchange-listing clawback rule, implemented through a separate policy referenced by the code26- Privacy and employee-data handling: lawful processing, notice, access, monitoring limitations, cross-border transfer controls, and incident-response obligations where applicable27- Corporate opportunity doctrine: officers and directors may not appropriate company opportunities for personal benefit; disclosure and approval procedures should be stated28- Board process conventions: board approval, delegation limits, and periodic or event-driven updates when law or listing standards change2930## 4. Analytical scaffolds3132- Draft the code as a standalone compliance document that can supersede fragmented legacy policies while remaining readable to employees, managers, officers, and directors33- Organize by topic areas that map to operational risk: general standards, conflicts of interest, healthcare interactions, financial integrity, records, data/privacy, reporting and investigations, public-company obligations, discipline, and administration34- For healthcare-interaction rules, define the approval chain for higher-risk arrangements, the treatment of meals and educational programs, and escalation for exceptions35- For transparency reporting, state who collects reportable information, how it is validated, how long records are kept, and when submissions or attestations occur36- For whistleblower protections, include four distinct concepts: internal reporting, external reporting, non-retaliation, and anonymous or confidential channels overseen by the audit committee or equivalent body37- For clawback, tie the code to the controlling securities-law and exchange-listing authorities, identify covered executives and covered incentive awards at a category level, and refer implementation details to the separate adopted policy38- For manufacturing and quality, make clear that compliance failures include falsification, omission, alteration, backdating, concealment, and failure to escalate deviations or adverse findings39- For privacy and monitoring, distinguish employee notice, legitimate business use, lawful monitoring, retention, cross-border transfer controls, and breach response obligations40- For issues reconciliation, treat each conflict or gap as a discrete item and resolve it by identifying the competing source language, the adopted position, the reason for adoption, and any residual action outside the code4142## 5. Vertical / structural / temporal relationships4344- Keep company-wide standards separate from role-specific standards, with extra detail for employees in regulated, finance, legal, quality, clinical, and commercial functions45- Make board-level governance provisions distinct from management implementation duties, so adoption, waiver approval, and periodic review are not buried in operational provisions46- Ensure the whistleblower section is substantively protective, not merely procedural, because a reporting mechanism without express anti-retaliation protection is incomplete47- Align healthcare-interaction requirements with any existing engagement controls in the source set so the code does not create a conflicting approval path48- Where source materials diverge, preserve the highest-control or most legally conservative position unless the source set provides a clear business reason to adopt a different rule49- If multiple source policies address the same topic, compare them side by side before drafting the final rule so the code reflects a deliberate resolution rather than an accidental blend5051## 6. Output structure conventions5253- Draft the code first as the primary deliverable and ensure it is complete, operative, and usable on its own before preparing any memorandum54- Use conventional code-of-conduct organization with clear headings, plain-English rules, and enforceable obligations rather than aspirational summaries55- Include a dedicated administration section covering adoption authority, amendment mechanics, periodic review, waiver approval, and distribution/acknowledgment expectations56- Use specific, named legal authorities in the text where the rule depends on a statute, regulation, exchange standard, or recognized doctrine57- Keep the tone formal, practical, and compliance-oriented; avoid commentary about drafting choices inside the code itself58- Prepare the issues reconciliation memorandum as a separate advisory work product organized by source conflict or gap, not as a narrative essay59- In the memorandum, state each conflict, the adopted resolution, the rationale, and any open follow-up action that remains outside the code60- End the memorandum with a concise Recommended Actions section naming the responsible role and a timing anchor tied to the closing or implementation milestone