A founder approves a software vendor while holding an advisory role at the vendor's company. An executive recommends a candidate whose spouse works for a competitor. A developer launches a side venture that uses knowledge gained from confidential product plans. None of these situations automatically proves misconduct, yet each can put a company's judgment, credibility, and legal position under pressure.
That's why the practical answer to what is a conflict of interest policy isn't just “a form employees sign.” It's a governance system that identifies competing interests, requires timely disclosure, assigns an independent review process, and records the action taken. For Washington State startups and technology companies, that system must account for equity, side businesses, overlapping board roles, close professional networks, and access to valuable data.
When Good Intentions Are Not Enough
A Seattle startup founder sits on the board of a small infrastructure company. The relationship began before the startup needed a new vendor, and the founder believes the vendor is qualified. During procurement, the founder tells the chief operating officer, “Everyone knows about the board role,” then stays in the room while the team compares proposals.
That informal disclosure may feel transparent. It still leaves unanswered questions. Was the founder permitted to participate? Who decided whether the relationship created a conflict? Did the company compare alternatives using consistent criteria? Where is the record showing that the board understood the relationship and approved the mitigation?
The same problem appears when an executive's spouse works for a competitor. The executive may never share confidential information, and the spouse may have no involvement in the relevant product. But if the executive participates in pricing, hiring, acquisition planning, or contract negotiations, the company needs a reliable process for evaluating the relationship rather than relying on personal assurances.
Practical rule: A disclosure is the beginning of the review, not the end of the analysis.
A written policy gives the organization a common vocabulary and a repeatable response. It can require disclosure before a decision, identify the person or committee responsible for review, require recusal where appropriate, and preserve the rationale in the company's records. Without those controls, similar situations may receive different treatment depending on who notices them or how persuasive the affected person is.
The policy should also sit alongside the company's broader governance documents. A shareholders agreement may address voting rights, information rights, transfer restrictions, or founder obligations, but it doesn't replace a conflict workflow for day-to-day decisions.
Conflicts aren't evidence that an organization employs bad actors. They're structural risks created by ordinary relationships, investments, family ties, outside work, and professional opportunities. Trust matters, but trust without documentation isn't a defensible control when a contract, hiring decision, or board vote is later challenged.
The Legal and Ethical Foundation of Conflict Policies
A conflict of interest policy is a formal governance document that defines circumstances in which personal interests could improperly influence professional judgment. It also establishes procedures for disclosure, review, recusal, mitigation, recordkeeping, and enforcement.
The modern policy model has a clear historical milestone. The OECD adopted its Recommendation on Guidelines for Managing Conflict of Interest in the Public Service on 28 May 2003, following expert review in 2002 and drafting work in early 2003. The OECD describes the recommendation as the first international benchmark in the field, defining a conflict as a clash between public duty and private interests that could improperly influence official responsibilities. That framework helped move conflicts from a broad ethics concern into a formal governance practice involving disclosure and decision controls. OECD Recommendation on Managing Conflict of Interest
Three functions of the policy
First, the policy protects the organization from avoidable legal and governance exposure. For federal employees, 18 U.S.C. § 208 prohibits personal and substantial participation in official matters affecting certain financial interests, including interests connected to a spouse, minor child, specified organizations, and entities with which the employee is negotiating future employment. Federal conflict-of-interest standards summarized by the Bureau of Justice Assistance
Second, it protects stakeholder trust. For U.S. nonprofits, the IRS expects a written process requiring disclosure of relevant facts, recusal from voting, identification of relationships or financial interests that create conflicts, and regular evaluation of the policy. IRS guidance on the purpose of a nonprofit conflict of interest policy
Third, it creates an auditable record of good-faith governance. A documented decision can show who disclosed the interest, who reviewed it, what facts were considered, whether the person left the discussion, and why the organization selected a particular mitigation. A policy that merely announces ethical values without assigning responsibility or preserving evidence doesn't perform those functions.
Businesses should treat the policy as part of corporate governance and compliance, not as a standalone acknowledgment. The strongest policies connect ethical expectations to contracts, procurement, hiring, board administration, and data protection.
Essential Elements Every Policy Must Include
A policy becomes usable when it answers practical questions before a conflict arises. Who must disclose? What counts as an interest? Who decides whether a conflict exists? What happens to the person's participation while the review is pending?
Scope definition
Start by identifying covered individuals. Depending on the organization, that group may include directors, officers, founders, employees with purchasing or hiring authority, consultants, advisors, and committee members. The policy should also identify covered interests, including ownership, compensation, family relationships, outside employment, advisory roles, board service, business opportunities, confidential information, and relationships with suppliers, customers, competitors, or applicants.
Sample language can be adapted:
“Financial interest” means a direct or indirect ownership, investment, compensation, lending, or economic interest that could reasonably appear to affect a covered person's judgment regarding an organizational matter.
The definition should be flexible enough to capture new arrangements without treating every ordinary social connection as disqualifying. “Family relationship” should identify close family members while allowing the organization to review relationships that, although not formally familial, could reasonably affect impartiality.
Disclosure procedures
Require disclosures at onboarding, on a recurring basis, and whenever a new circumstance arises. The form should ask for facts, not conclusions. “No conflict” is less useful than a description of the outside company, the person's role, the financial connection, the relevant organizational matter, and the expected duration.
Use a secure system or controlled form, assign a recipient, and set a rule for urgent disclosures before a decision or vote. The person should not have to determine alone whether the situation legally qualifies as a conflict.
Review and decision process
Name the decision-maker, such as a general counsel, compliance officer, independent director, or designated committee. The reviewer should assess whether the conflict can be eliminated, managed through recusal, addressed with controls, or accepted with documented reasoning.
The record should identify the matter, the disclosed interest, the reviewer, the decision, the mitigation, and any follow-up date. Participation restrictions should apply while the analysis is pending when the circumstances could affect a material decision.
Enforcement and consequences
A policy should explain consequences for late, incomplete, or intentionally false disclosures. Remedies may include removal from the decision, contract reassignment, additional training, disciplinary action, clawback analysis, or escalation to the board. An appeal process can reduce arbitrary enforcement, but it shouldn't allow the affected person to control the appeal.
Avoid two drafting failures. A policy that says “avoid conflicts” without defining a process is too vague to enforce. A policy that requires disclosure of every minor social connection creates fatigue and encourages employees to treat the form as meaningless. Precision and proportionality work better than either extreme.
Recognizing Actual, Potential, and Perceived Conflicts
The safest policy distinguishes among actual, potential, and perceived conflicts. These categories help employees report concerns before a situation becomes a direct violation.
| Conflict type | What it means | Business example |
|---|---|---|
| Actual | A current personal interest directly competes with professional duty | An executive negotiates with a company in which the executive owns stock |
| Potential | A foreseeable situation could develop into a competing interest | An employee's close friend works for a vendor seeking a contract |
| Perceived | A reasonable observer could question impartiality, even without actual bias | A hiring manager evaluates a close friend for an important role |
An actual conflict usually demands an immediate control. The affected person may need to stop participating, transfer responsibility, or obtain an independent determination. For example, a board member whose company provides services to the organization shouldn't influence the negotiation or vote on that company's engagement.
A potential conflict calls for monitoring and advance planning. A close friendship with a vendor may not compromise a purchasing decision, but the relationship could become more consequential if the employee receives a referral payment, the vendor becomes a strategic partner, or the employee begins discussing outside work with the vendor.
Perceived conflicts require judgment because appearances can damage trust even when no improper action occurred. A hiring manager might believe a friend is the strongest candidate, yet other employees or applicants may reasonably question whether the process was fair. Disclosure and reassignment can protect both the manager and the organization.
The comparison matters because a narrow policy creates false comfort. Regulators and governance frameworks increasingly address perceived and potential conflicts alongside actual ones, as reflected in broader policy guidance covering third-party relationships, remuneration, and confidential information. Recent conflict-of-interest policy guidance from Australia's National Anti-Corruption Commission
For managers handling the human side of these situations, a practical guide to resolving employee conflict can complement, but not replace, the organization's formal disclosure and recusal process.
Turning Policy into Operational Practice
A policy stored in a shared drive doesn't protect a company by itself. Protection comes from repeated actions that make disclosure, assessment, mitigation, and oversight part of normal work.
Build the workflow around events
The first disclosure should occur during onboarding, before a new employee or director receives authority over purchasing, hiring, contracts, investments, or sensitive data. The process should then require recurring reaffirmation and an event-triggered update when a person accepts outside work, acquires a relevant interest, joins a board, begins negotiating employment, or develops a relationship with a vendor or competitor.
The organization should maintain a conflict register. It doesn't need to expose sensitive personal details to everyone, but it should preserve enough information to show:
- The reported facts: Who disclosed, when, and what relationship or interest was identified.
- The decision: Whether the reviewer found an actual, potential, or perceived conflict.
- The mitigation: Recusal, reassignment, information restriction, independent review, divestment, or another documented control.
- The follow-up: Any expiration, monitoring obligation, training requirement, or later review.
Assign ownership and evidence
The policy should name the person or committee receiving disclosures and define the authority to require recusal. A founder shouldn't be the sole reviewer of a conflict involving the founder's outside company. A board committee, independent director, or external counsel may be needed where leadership's own interests are involved.
The OECD framework emphasizes transparency, individual responsibility, and an organizational culture that doesn't tolerate conflicts. OECD guidance on managing conflict-of-interest systems supports the practical conclusion that culture and controls must operate together. Employees need training that explains why disclosure protects them, while managers need consistent consequences when people conceal relevant facts.
Training should use the company's real decisions. A procurement example, a hiring example, and a data-access example will produce better recognition than a generic ethics presentation. Audits can then test whether forms were completed, reviewers acted on them, recusals were recorded, and decision-makers followed the restrictions.
Board actions should also be documented properly. A board resolution can record approval of the policy, appointment of the review authority, or a specific mitigation decision when board-level action is appropriate.
Unique Challenges for Startups and Technology Companies
Traditional policies often assume a stable hierarchy, clear job boundaries, and limited outside activity. Technology startups operate differently. Founders may serve on multiple boards, hold equity in vendors, advise companies in adjacent markets, and explore side ventures while their own product is still developing.
Equity creates particular difficulty because the interest may be indirect or difficult for colleagues to see. A founder may hold shares through an investment vehicle. An employee may receive options in a competitor. An executive may have a future compensation arrangement with a partner or potential acquirer. The policy should require disclosure of the relationship and its economic character without demanding unnecessary personal financial detail.
Side ventures also create overlapping obligations. A developer working on an open-source project may contribute code that intersects with the employer's product roadmap. A product manager may build a separate tool using general skills but rely on company data, customer information, internal documentation, or confidential plans. The conflict policy should coordinate with intellectual-property, confidentiality, trade-secret, invention-assignment, and data-access rules.
Washington State's Greater Puget Sound technology ecosystem adds a practical complication. Professional networks are dense, and the same people may appear as investors, advisors, former colleagues, board members, customers, and competitors across multiple companies. A generic rule that prohibits all relationships is unworkable. A vague rule that ignores those relationships is dangerous.
A policy should address:
- Equity and compensation: Ownership, options, carried interests, referral payments, and contingent compensation.
- External roles: Board seats, advisory positions, consulting work, angel investments, and accelerator relationships.
- Side projects: Overlapping products, open-source contributions, customer relationships, and use of company resources.
- Data access: Confidential product plans, customer data, security information, pricing, source code, and nonpublic business intelligence.
The board structure should match the company's real decision rights, which makes a tailored board of directors structure especially important for growing startups. A policy should define who can approve an outside role and who must step aside when the founder or an executive is personally involved.
Implementing and Maintaining Your Policy Over Time
Implementation should follow the company's actual governance calendar rather than occur as a disconnected compliance project.
Approve and communicate
Leadership or the board should approve the policy through a documented action and identify the owner responsible for administration. Covered individuals should receive the policy, the disclosure form, and instructions explaining where to report questions or new interests.
Training should explain the reasoning behind the rules. Employees need to understand that disclosure doesn't automatically mean wrongdoing or removal. It gives the organization a chance to choose a proportionate response before someone participates in a decision that later appears compromised.
Collect the first disclosures
The initial collection should be organized by role and risk. Directors, founders, executives, procurement personnel, hiring managers, finance staff, and employees with sensitive data access may need more detailed questions than employees with no decision-making authority.
The form should be short enough to complete accurately. Excessive questions encourage rushed answers, while vague questions produce unreliable disclosures. A useful form asks about outside employment, ownership, board and advisory roles, close relationships connected to company decisions, compensation arrangements, side businesses, and access to information that could benefit an outside venture.
Integrate the policy into existing decisions
The conflict check should appear where decisions happen:
- Board meetings: Add a disclosure prompt to the agenda and record recusals in the minutes.
- Hiring: Ask the hiring manager to identify personal relationships before interviews and selection.
- Procurement: Require decision-makers to disclose vendor ownership, referral compensation, and close relationships.
- Contract approvals: Screen for outside roles, competing obligations, and contingent compensation.
- Data access: Restrict information where an outside venture or competitor relationship creates a risk.
Federal contractor rules illustrate why operational controls matter. The FAR requires contractors to identify and prevent personal conflicts involving covered employees and prohibits use of nonpublic information obtained through contract work for personal gain. It also generally restricts knowingly awarding contracts to government employees or entities they own, substantially own, or control. FAR Part 3 on improper business practices and personal conflicts
Review, test, and update
A sensible maintenance program includes an annual policy review and a biennial external audit. The annual review should examine new business models, equity arrangements, data practices, outside roles, and recurring disclosure problems. The external audit should test whether the process works in practice, not merely whether the document contains the expected headings.
California's FPPC issued multiple 2025 quarterly updates affecting filing dates, electronic posting, and conflict-of-interest code provisions, showing that compliance obligations can change within months rather than years. Recent policy material addressing recurring review and reporting mechanisms
Legal counsel should review the policy when the company enters a regulated market, adopts a new equity structure, launches a side-business program, acquires another company, expands data access, adds board members, or receives a concern about undisclosed interests. The right question isn't whether the company has a policy. It's whether the company can show that people knew the rule, disclosed the issue, received an independent review, and followed the recorded decision.
By Design Law Firm & Legal Consultancy, PLLC advises startups and established companies on conflict policies, corporate governance, contracts, data privacy, and practical compliance workflows. Visit By Design Law Firm & Legal Consultancy, PLLC to discuss a policy that fits the company's ownership structure, technology, decision processes, and Washington State operations.





