Skip to main content
Category: Ethics and Conduct

Conflict of Interest Policy

Also known as: COI Policy, Conflicts of Interest Policy, COI Policy
Simply put

A conflict of interest policy is a formal organizational document that sets out procedures for handling situations where an individual's personal interests might conflict with the interests of the organization they serve. It typically defines what counts as a conflict, identifies who the policy applies to, and establishes a process for disclosing and managing actual or potential conflicts when they arise. The aim is to help the organization identify and address these situations consistently rather than leaving them to individual judgment.

Formal definition

A conflict of interest policy is a written governance instrument that defines the categories of actual, potential, and perceived conflicts within an organization, specifies its scope of application (for example, directors, officers, employees, or volunteers), and establishes procedures for disclosure, review, recusal, and management of conflicts. In practice, such policies commonly assign responsibility for evaluating disclosed conflicts and determining appropriate handling, though the specific structure and authority allocation vary by organization type and jurisdiction. For certain entities, such as U.S. nonprofit organizations completing IRS Form 1023, adopting a conflict of interest policy is a recognized governance practice intended to ensure that a process exists for addressing conflicts, but the requirement, scope, and enforceability of any given policy depend on the entity's legal form, sector, and applicable rules. This entry is educational and not legal, audit, or compliance advice.

Why it matters

A conflict of interest policy matters because conflicts, when left unaddressed, can undermine the integrity of an organization's decisions and erode trust among stakeholders, regulators, and the public. When an individual's personal interests may contradict the interests of the organization they serve, decisions can be tainted by the perception or reality of self-dealing. A formal policy is intended to help ensure that when actual or potential conflicts arise, the organization has a consistent process in place to identify and address them, rather than relying on ad hoc individual judgment that may vary from person to person.

For certain organizations, adopting such a policy is a recognized governance practice tied to specific compliance contexts. For example, U.S. nonprofit organizations completing IRS Form 1023 are prompted to indicate whether they have adopted a conflict of interest policy, which the IRS describes as a means of helping ensure a process exists for addressing conflicts. It is important to note, however, that whether any given policy is legally required, and the scope and enforceability of its provisions, depends on the entity's legal form, sector, and applicable rules. A policy is a governance instrument that supports good practice; its mere existence does not by itself guarantee that conflicts will be handled effectively without disciplined disclosure, review, and follow-through.

Who it's relevant to

Boards and governance committees
Boards and their governance or nominating committees generally hold oversight responsibility for whether a conflict of interest policy exists, is appropriate to the organization, and is periodically reviewed. Directors are also frequently within the scope of the policy themselves, meaning they are expected to disclose their own conflicts and recuse where appropriate. The board's role is typically one of oversight and, in many structures, final review of significant disclosed conflicts, rather than day-to-day administration.
Compliance and legal functions
Compliance officers and general counsel typically draft, maintain, and administer the policy, manage the disclosure process, and advise on how individual conflicts should be handled. Their involvement helps ensure the policy reflects applicable rules for the entity's legal form and sector. This work sits within the compliance discipline and should not be confused with the board's oversight duty or with independent assurance functions.
Nonprofit organizations
For U.S. nonprofit organizations, adopting a conflict of interest policy is a recognized governance practice associated with the IRS Form 1023 process, which asks whether such a policy has been adopted. The policy is intended to demonstrate that a process exists for addressing conflicts, though the precise requirement and enforceability depend on the organization's status and applicable rules.
Officers, employees, and volunteers
Individuals within the policy's defined scope are responsible for understanding what counts as a conflict, disclosing actual or potential conflicts affecting them, and complying with any recusal or management steps the policy requires. The exact obligations depend on how the specific policy defines scope and procedures.

Inside COI Policy

Scope and Coverage
Defines who is subject to the policy (for example, directors, officers, employees, and in some cases contractors or key vendors) and the types of relationships, interests, and transactions that fall within its reach, such as financial interests, outside employment, family relationships, gifts, and board interlocks.
Definition of a Conflict
Articulates what constitutes an actual, potential, or perceived conflict between an individual's private interests and the interests of the organization. Clear definitions help distinguish situations requiring disclosure from ordinary business dealings, though application often depends on specific facts.
Disclosure Requirements
Sets out how and when individuals must disclose interests, typically through an initial declaration, periodic (often annual) attestations, and ad hoc disclosure when circumstances change. Specifies the recipient of disclosures, which is commonly a compliance function, general counsel, or a designated committee.
Review and Determination Process
Describes how disclosed matters are assessed and by whom, including the criteria used to decide whether a conflict exists and what action is warranted. Accountability for determinations generally rests with a governance, compliance, or committee function rather than the individual disclosing.
Management and Mitigation Measures
Identifies measures used to manage identified conflicts, such as recusal from relevant discussions and votes, information barriers, divestment, reassignment of duties, or enhanced oversight. The appropriate measure typically depends on the nature and severity of the conflict.
Recusal and Decision-Making Protocols
Establishes expectations for a conflicted individual to abstain from participating in or influencing decisions where they have an interest, and how the abstention is recorded, particularly at the board and committee level.
Recordkeeping and Documentation
Provides for maintaining records of disclosures, determinations, and mitigation actions to support accountability, auditability, and, where applicable, demonstration of compliance to regulators or external assurance providers.
Roles and Accountability
Assigns responsibility across the organization, distinguishing the board's oversight of the policy and of conflicts involving directors, management's implementation and enforcement, and any compliance or assurance function's monitoring role.
Enforcement and Consequences
Describes the consequences of non-compliance, such as disciplinary measures, and how breaches are escalated, which reinforces that the policy is more than an aspirational statement.

Common questions

Answers to the questions practitioners most commonly ask about COI Policy.

Does a conflict of interest policy only apply to directors and senior executives?
No. While directors and senior executives are often the focus because of their decision-making authority, a conflict of interest policy typically extends to a broader population that may include employees at various levels, officers, and in some cases contractors, agents, or others acting on the organization's behalf. The appropriate scope depends on where conflicts realistically arise and on applicable legal, listing, and sector requirements. Organizations generally define scope explicitly in the policy itself, and the precise coverage is a matter for each entity's judgment based on its structure and risk profile.
Does having a conflict of interest mean someone has done something wrong?
Not necessarily. A conflict of interest is generally a situation in which a person's competing interests could improperly influence, or appear to influence, the exercise of their duties; it is a condition, not by itself misconduct. Many conflicts are unavoidable and are managed appropriately through disclosure, recusal, or other measures. Wrongdoing typically arises from failing to disclose a conflict or from allowing it to improperly affect a decision, rather than from the existence of the conflict alone. This distinction is central to how most policies frame their disclosure and management provisions.
How should conflicts be disclosed and recorded under a typical policy?
Policies commonly establish a defined disclosure process, which may include disclosure on appointment or hire, periodic (often annual) declarations, and prompt disclosure when a new conflict arises. Disclosures are typically recorded in a register or similar record that management or the relevant governance function maintains. The specific mechanism, timing, and custodian of the record vary by organization and should be set out clearly in the policy. This is generally treated as a management and administrative responsibility, with board or committee oversight of the framework as a whole.
Who owns the conflict of interest policy and who oversees its operation?
Accountability is generally layered. The board or a designated committee (such as an audit, governance, or nominating committee, depending on the organization) typically holds oversight responsibility for approving the policy and monitoring that a credible process exists. Management is generally responsible for operating the policy day to day, maintaining records, and escalating matters. Assurance functions, where they review the policy, generally provide independent evaluation of design and operating effectiveness rather than owning the control. The exact allocation depends on the organization's structure and any applicable requirements.
How are disclosed conflicts typically managed once identified?
Management approaches vary with the nature and severity of the conflict and may include recusal from relevant discussions and decisions, restricting access to certain information, reassigning responsibilities, obtaining independent review, or in some cases requiring divestment of the competing interest. Policies generally specify who decides on the appropriate response and how that decision is documented. The suitable response depends on the specific facts, and determining it is a matter of judgment for the responsible decision-maker within the policy's framework.
How often should a conflict of interest policy and its declarations be reviewed?
Periodic review is a common feature, with many organizations refreshing declarations on a regular cycle (frequently annual) and reviewing the policy itself at defined intervals or in response to regulatory change, organizational change, or lessons from incidents. The appropriate frequency is not fixed by a single universal standard and depends on the organization's risk profile and any applicable legal or listing requirements. Organizations generally set and document the review cadence within the policy or a related governance calendar.

Common misconceptions

A conflict of interest policy exists to prevent employees and directors from ever having outside interests.
Such policies generally aim to identify, disclose, and manage conflicts rather than to prohibit all outside interests. Many conflicts can be managed through disclosure and mitigation; the policy's purpose is typically to ensure that private interests do not improperly influence organizational decisions.
Only actual conflicts involving money need to be disclosed.
Many policies address actual, potential, and perceived conflicts, and cover non-financial interests such as family relationships, outside roles, and personal loyalties. Whether a given situation requires disclosure typically depends on the policy's definitions and the specific facts.
Adopting a written policy is sufficient to satisfy governance expectations.
A policy on paper is generally not enough. Effective conflict management usually depends on operating effectiveness, including consistent disclosure, review, recusal, recordkeeping, and enforcement. A well-designed policy that is not applied in practice provides limited assurance.

Best practices

Require both periodic attestations and ad hoc disclosure so that new or changed interests are captured promptly rather than only at fixed intervals.
Clearly assign accountability, distinguishing the board's oversight of director conflicts from management's day-to-day implementation and any compliance or assurance function's monitoring role.
Establish and document recusal protocols for board and committee decisions, recording abstentions in the minutes to evidence that conflicted individuals did not influence the outcome.
Maintain auditable records of disclosures, determinations, and mitigation actions to support accountability and, where applicable, demonstrate compliance to regulators or assurance providers.
Define actual, potential, and perceived conflicts and give practical examples so individuals can recognize situations that warrant disclosure, recognizing that application depends on specific facts.
Test operating effectiveness periodically rather than relying on the existence of a written policy, and tailor scope and mitigation measures to the organization's jurisdiction, sector, and entity type. This guidance is educational and not legal, audit, or compliance advice.