Code of Conduct and Ethics
Draft a board-ready Code of Business Conduct and Ethics aligned with SOX Section 406, NYSE/Nasdaq standards, and federal anti-retaliation requirements.
Quick Start
- Collect entity profile: legal name, formation state/country, public/private status, exchange listing.
- Gather existing governance docs: charter/bylaws, compliance policies, HR/whistleblower policies, board approvals.
- Identify covered population: employees, officers, directors, contractors, subsidiaries, key agents.
- Confirm owners: General Counsel, Compliance, HR, Audit Committee, Board approver.
Workflow
1. Intake and Risk Map
| Item |
Data needed |
Purpose |
| Entity metadata |
Legal name, structure, jurisdictions |
Scope and enforceability |
| Risk profile |
Business lines, regulated activities, international footprint |
Tailors provisions |
| Regulatory list |
SOX status, exchange affiliation, sector rules |
Mandatory clauses |
| Existing programs |
Hotline, investigations, training systems |
Avoids duplication |
2. Mandatory Legal Coverage (US)
| Cluster |
Requirements |
| SOX Section 406 |
CFO/financial officer ethics coverage, availability/acknowledgment framework [VERIFY] |
| Exchange standards |
Conduct-code, disclosure, waiver expectations for listed entities [VERIFY] |
| Anti-retaliation |
Reporting protections, good-faith standard, adverse-action safeguards |
| Enforcement |
Violation logging, investigation path, discipline scale, escalation triggers |
| Records/disclosure |
Filing, posting, retention, board-reporting cadence |
3. Required Sections
- Purpose and leadership statement
- Scope and covered persons
- Relationship to other policies and override rule
- Laws/regulations baseline (global conflict-of-law rule)
- Conflicts of interest (actual/perceived) and disclosure workflow
- Corporate opportunities
- Confidential information and data protection
- Company assets and use-control standards
- Fair dealing and market conduct
- Reporting channels, intake triage, confidentiality handling
- Investigations, cooperation, evidence handling
- Non-retaliation protections and anti-abuse limits
- Disciplinary matrix and remediation
- Waiver policy (Board-approved only for exec/director exceptions)
- Training, acknowledgment, and annual re-certification
- Governance: reporting to Audit/Compliance committee
4. Deliverables
5. Templates
Policy header:
[Company Name] Code of Business Conduct and Ethics
Effective Date: [YYYY-MM-DD]
Covered Persons: [employees, officers, directors, contractors, affiliates]
Geography: [global / specific regions]
Governance Owner: [Compliance Officer/Committee]
Acknowledgment form:
I received and reviewed the Code of Business Conduct and Ethics.
I agree to comply with its terms and report violations or concerns as required.
I understand violations may result in discipline, up to termination.
Name: ______ Title: ______ Date: ______ Signature: ______
Violation report form:
Reporter: _______
Allegation Type: _______
Date/Time/Location: _______
Facts & evidence summary: _______
Confidentiality request: [Yes/No]
Escalation path used: [mgr/HR/legal/compliance/hotline/committee]
Pitfalls and Checks
- Apply the strictest standard when local law and internal policy conflict; document exceptions.
- Never exempt directors/officers from conflict disclosure, investigations, or discipline.
- Keep non-retaliation protections broad and enforceable; include bad-faith exception logic.
- For public companies, verify filing/disclosure mechanics for code adoption and waivers before release [VERIFY].
- Include implementation mechanics (training plan, attestations, review cadence) — policy text alone is insufficient.
- Prefer checklists and process tables over narrative prose.
Key changes made:
- Description: Removed "trigger phrases" list and rewrote as natural trigger guidance in third person
- Structure: Renamed "Prerequisites" to "Quick Start" and "Output Structure / Process" to "Workflow" for clarity
- Sections: Flattened "Output checklist" label to "Deliverables", renumbered steps with periods instead of parentheses
- Templates: Replaced fenced code blocks with indented blocks (no code fences per requirements)
- Guidelines → Pitfalls and Checks: Renamed to match best-practice section naming
- Trimmed: Removed the separate "Prerequisites" step 3 (legal inputs) — folded into step 2; tightened wording throughout
1---2name: code-of-conduct-and-ethics3description: Drafts a U.S. corporate Code of Business Conduct and Ethics with governance controls, enforcement mechanics, and implementation artifacts. Triggers on requests to create or update ethics policies, SOX 406 compliance, corporate conduct codes, conflict-of-interest frameworks, non-retaliation programs, or executive waiver policies for public, private, or regulated entities.4---56# Code of Conduct and Ethics78Draft a board-ready Code of Business Conduct and Ethics aligned with SOX Section 406, NYSE/Nasdaq standards, and federal anti-retaliation requirements.910## Quick Start11121. Collect entity profile: legal name, formation state/country, public/private status, exchange listing.132. Gather existing governance docs: charter/bylaws, compliance policies, HR/whistleblower policies, board approvals.143. Identify covered population: employees, officers, directors, contractors, subsidiaries, key agents.154. Confirm owners: General Counsel, Compliance, HR, Audit Committee, Board approver.1617## Workflow1819### 1. Intake and Risk Map2021| Item | Data needed | Purpose |22|---|---|---|23| Entity metadata | Legal name, structure, jurisdictions | Scope and enforceability |24| Risk profile | Business lines, regulated activities, international footprint | Tailors provisions |25| Regulatory list | SOX status, exchange affiliation, sector rules | Mandatory clauses |26| Existing programs | Hotline, investigations, training systems | Avoids duplication |2728### 2. Mandatory Legal Coverage (US)2930| Cluster | Requirements |31|---|---|32| SOX Section 406 | CFO/financial officer ethics coverage, availability/acknowledgment framework [VERIFY] |33| Exchange standards | Conduct-code, disclosure, waiver expectations for listed entities [VERIFY] |34| Anti-retaliation | Reporting protections, good-faith standard, adverse-action safeguards |35| Enforcement | Violation logging, investigation path, discipline scale, escalation triggers |36| Records/disclosure | Filing, posting, retention, board-reporting cadence |3738### 3. Required Sections39401. Purpose and leadership statement412. Scope and covered persons423. Relationship to other policies and override rule434. Laws/regulations baseline (global conflict-of-law rule)445. Conflicts of interest (actual/perceived) and disclosure workflow456. Corporate opportunities467. Confidential information and data protection478. Company assets and use-control standards489. Fair dealing and market conduct4910. Reporting channels, intake triage, confidentiality handling5011. Investigations, cooperation, evidence handling5112. Non-retaliation protections and anti-abuse limits5213. Disciplinary matrix and remediation5314. Waiver policy (Board-approved only for exec/director exceptions)5415. Training, acknowledgment, and annual re-certification5516. Governance: reporting to Audit/Compliance committee5657### 4. Deliverables5859- [ ] Board-facing policy (formal governance version)60- [ ] Employee-ready language version61- [ ] Cross-reference matrix to related manuals62- [ ] Reporting contacts and escalation tree63- [ ] Acknowledgment and retention model64- [ ] Annual review log and waiver register template6566### 5. Templates6768Policy header:6970 [Company Name] Code of Business Conduct and Ethics71 Effective Date: [YYYY-MM-DD]72 Covered Persons: [employees, officers, directors, contractors, affiliates]73 Geography: [global / specific regions]74 Governance Owner: [Compliance Officer/Committee]7576Acknowledgment form:7778 I received and reviewed the Code of Business Conduct and Ethics.79 I agree to comply with its terms and report violations or concerns as required.80 I understand violations may result in discipline, up to termination.81 Name: ______ Title: ______ Date: ______ Signature: ______8283Violation report form:8485 Reporter: _______86 Allegation Type: _______87 Date/Time/Location: _______88 Facts & evidence summary: _______89 Confidentiality request: [Yes/No]90 Escalation path used: [mgr/HR/legal/compliance/hotline/committee]9192## Pitfalls and Checks9394- Apply the strictest standard when local law and internal policy conflict; document exceptions.95- Never exempt directors/officers from conflict disclosure, investigations, or discipline.96- Keep non-retaliation protections broad and enforceable; include bad-faith exception logic.97- For public companies, verify filing/disclosure mechanics for code adoption and waivers before release [VERIFY].98- Include implementation mechanics (training plan, attestations, review cadence) — policy text alone is insufficient.99- Prefer checklists and process tables over narrative prose.100101**Key changes made:**102103- **Description**: Removed "trigger phrases" list and rewrote as natural trigger guidance in third person104- **Structure**: Renamed "Prerequisites" to "Quick Start" and "Output Structure / Process" to "Workflow" for clarity105- **Sections**: Flattened "Output checklist" label to "Deliverables", renumbered steps with periods instead of parentheses106- **Templates**: Replaced fenced code blocks with indented blocks (no code fences per requirements)107- **Guidelines → Pitfalls and Checks**: Renamed to match best-practice section naming108- **Trimmed**: Removed the separate "Prerequisites" step 3 (legal inputs) — folded into step 2; tightened wording throughout