How to build a conflict of interest disclosure process that actually works
Ask most compliance teams if they have a conflict of interest policy, and the answer is yes. Ask if employees actually use the disclosure process behind it, and the answer gets a lot shakier.
That gap, between having a policy and having a process people actually follow, is where the risk lives. A policy tells people what a conflict is. A disclosure process determines whether anyone surfaces one before it becomes a problem. Get the process wrong, too cumbersome, too unclear, too dependent on individual initiative, and you will not know about conflicts until they surface on their own terms: a whistleblower report, a procurement audit, a press inquiry.
Get it right, and disclosure becomes the path of least resistance for employees at every level, not something they route around.
What is conflict of interest disclosure?
Conflict of interest disclosure is the formal process by which an employee, board member, or contractor identifies and reports a situation where their personal interests could influence (or appear to influence) their professional judgment or decisions.
A disclosure is a transparency mechanism, not an accusation: it gives the organization a chance to assess the situation early and put the right controls in place before any decision is affected.
There are two types of disclosure that a well-designed process needs to handle:
Proactive disclosure happens before a conflict becomes active, during onboarding, at the start of a new project, or through periodic declarations. An employee discloses a financial interest in a supplier before any procurement decision is made. A new hire declares a close relationship with someone in a competing role.
Reactive disclosure happens when a conflict arises unexpectedly, a new relationship, an inheritance, a job offer from a client. The process needs to make it equally easy to disclose in the moment as it is to complete an annual form.
Both matter. Most programs handle the annual cycle reasonably well. The reactive pathway is where gaps appear.
Why disclosure processes fail
The reasons are predictable, and every one of them is fixable.
The process is too difficult. If disclosing a conflict requires finding the right form, emailing the right person, and waiting for a response that may never come, many employees will decide that their situation probably does not qualify and move on. The disclosure threshold in most organizations is not legal, it is friction. Lower the friction, and disclosure rates rise.
Employees do not know what to disclose. Most people understand the obvious cases, a family member in a supplier company, a financial stake in a client. But the situations that create real risk are often subtler: a close friendship with someone in a competing role, a board seat that used to be irrelevant but now intersects with a new business line, hospitality that has accumulated into an implicit expectation. Without clear guidance on what triggers a disclosure, employees make their own judgment calls, and they are not always well-calibrated.
There is no feedback loop. An employee discloses a conflict and hears nothing for three weeks. They do not know whether the disclosure was received, who reviewed it, or what the outcome was. Over time, the rational conclusion is that disclosures disappear into a system that does not function. The next time a potential conflict arises, they hesitate.
The culture does not support it. A disclosure process is only as strong as the culture it operates in. If employees believe that raising a conflict will attract scrutiny they do not want, or that colleagues who disclose are treated differently, they will not disclose. Psychological safety and disclosure rates move together: organizations that invest in one tend to see gains in the other.
The five steps of an effective disclosure process
1. Identify what must be disclosed
The first job of a disclosure process is to define the categories employees need to think about. These typically include:
Financial interests in suppliers, clients, or competitors (shares, loans, ownership stakes)
Personal relationships with people involved in decisions the employee influences (hiring, procurement, performance management, contract awards)
Outside employment, consulting work, or board roles that intersect with the employee's responsibilities
Gifts, hospitality, or other benefits received from parties with whom the organization does business
Any situation where a reasonable person could conclude that the employee's judgment might be affected
A common standard is: when in doubt, disclose. A conflict that's disclosed and assessed as low-risk costs almost nothing. An undisclosed conflict that surfaces later carries the full weight of what was not said.
For a more detailed breakdown of the situations a disclosure process needs to cover, see our guide to common examples of conflict of interest in the workplace.
2. Make the disclosure channel easy to use
The channel matters as much as the process. If the mechanism for disclosure is a PDF form submitted by email to a generic compliance inbox, many disclosures will not happen. The employee either cannot find the form, is unsure who to address the email to, or concludes that the process is not worth the effort for something they are already uncertain about.
An effective disclosure channel has a few non-negotiable characteristics:
Accessible from any device, without requiring IT support or special permissions
Available in the languages employees work in, particularly in multinational organizations
Structured enough to guide the employee through what information to provide, without requiring them to write a memo
Clear about what happens next: who will review the disclosure, when they can expect a response, and what confidentiality protections apply
For organizations managing disclosures at scale, a dedicated conflict of interest management platform removes most of the friction by providing a structured intake form, automated routing to the right reviewer, and a secure audit trail, without requiring employees to navigate a general compliance inbox.
3. Route disclosures to the right reviewer
A disclosure that sits in someone's inbox with nobody acting on it is not materially different from a disclosure that was never made. The review step is where the process either works or stalls.
Define routing logic in advance, don't improvise it. Common practice is to route to direct line managers for low-sensitivity cases, to compliance or legal for anything involving senior employees, procurement decisions, or financial interests, and to an independent review committee for board members or executive leadership.
The reviewer's job is to assess whether the conflict creates a meaningful risk, and if so, what controls are appropriate. Common mitigations include recusal from the relevant decision, an independent second sign-off, a reporting line change, or in higher-risk cases, divestment of the financial interest.
Document every assessment: what was disclosed, who reviewed it, what the risk assessment concluded, and what mitigation the reviewer agreed to. That documentation is the audit trail. Without it, the organization cannot demonstrate that a conflict was managed even when it was.
4. Close the loop with the person who disclosed
The feedback loop is where most programs fall short, and where trust in the process is made or lost.
When someone discloses a conflict, they want to know three things: that the disclosure was received, that someone is taking it seriously, and what the outcome is. The response does not need to be lengthy. But it needs to exist, and it needs to arrive within a reasonable time.
Organizations that acknowledge receipt promptly, provide a timeline for review, and communicate the outcome clearly earn something valuable: employees who see that disclosure leads to a fair, confidential, responsive process are more likely to disclose again, and more likely to tell colleagues the process works.
5. Build in periodic renewal
A disclosure made at onboarding may be outdated within twelve months. Relationships change. Business interests evolve. A supplier that was irrelevant two years ago may now be at the center of a procurement decision.
An effective disclosure process does not treat the initial disclosure as permanent. It builds in annual or semi-annual renewal cycles, where employees confirm that their previously declared interests remain accurate and identify any new situations that have arisen. It also builds in event-based triggers: a role change, a new vendor relationship, a promotion into a decision-making position.
Renewal rates are a useful health metric for the program as a whole. A high initial participation rate with low renewal completion means the program is running good campaigns that are not holding. Tracking both, and acting on the gaps, is what separates programs that function from ones that only appear to.
Regulatory requirements for conflict of interest disclosure
Depending on your organization's geography and sector, conflict of interest disclosure may be a legal requirement rather than a governance best practice.
EU Whistleblowing Directive (2019/1937): Requires organizations with 50 or more employees to establish internal reporting channels for breaches of EU law, including conflicts of interest in public procurement. Member states have implemented this into national law with varying scope.
UK Bribery Act 2010: While not a disclosure law in the narrow sense, the Act's adequate procedures defense requires organizations to demonstrate that they have controls (including disclosure processes) to prevent bribery facilitated by conflicts of interest.
GDPR: Disclosure processes handle personal data. How that data is collected, stored, and accessed must comply with applicable data protection requirements, including data minimization, access controls, and retention limits.
Sector-specific requirements: Financial services, healthcare, public procurement, and listed companies face additional requirements under MiFID II, CSRD, the EU Public Procurement Directive, and similar frameworks. In these sectors, the bar for documentation and audit trail is higher.
For a full overview of the legal landscape across key markets, our conflict of interest policy guide covers the regulatory requirements organizations should reflect in their policies and disclosure procedures.
What good looks like in practice
A well-designed conflict of interest disclosure process has a few distinguishing characteristics.
It is proactive, not reactive. The process nudges employees to think about potential conflicts before decisions are made, rather than asking them to explain afterward.
It is proportionate. The process for a low-level employee disclosing a minor outside interest is not the same as the process for a senior executive disclosing a board seat at a competitor. Proportionality reduces burden without creating gaps.
It is documented. The organization records every disclosure, assessment, and outcome in a system it can query. When a question arises about how a conflict was handled, the answer is in the audit trail.
And it is trusted. Employees believe that disclosure will be handled fairly and confidentially, and they have seen enough follow-through to act on that belief.
That last element is the one that cannot be designed in. It has to be earned, through consistent follow-up, clear communication, and a track record of handling conflicts fairly regardless of seniority. The process sets the conditions. The culture determines whether it works.
How SpeakUp Paths supports the disclosure process
Managing conflict of interest disclosures manually through shared inboxes, spreadsheets, or annual email campaigns works, until it doesn't. Then it really doesn't. The hidden risks in manual disclosure programs aren't always visible until an incident makes them so: a disclosure nobody routed to the right reviewer, a renewal cycle that lapsed, a mitigation someone agreed to but never tracked to completion.
For compliance teams managing disclosures across multiple regions, roles, and regulatory frameworks, that gap is exactly what SpeakUp Paths closes: easy submission for employees, structured review for your compliance team, and complete documentation for auditors, all in one place. Employees submit disclosures through a structured, multilingual intake form. Disclosures route automatically to the right reviewer based on configurable logic. The platform records every assessment and outcome in a centralized audit trail, and renewal cycles run through automated campaigns with manager-level visibility into completion status.
Book a demo to see how SpeakUp Paths handles the disclosure process end to end.
FAQ
What is a conflict of interest disclosure?
A conflict of interest disclosure is a formal notification an employee, board member, or contractor makes to their organization, flagging a situation where their personal interests could influence (or appear to influence) their professional decisions. Rather than an accusation, it's a transparency step that lets the organization assess the situation and put the right controls in place.
Who is required to make conflict of interest disclosures?
Disclosure requirements typically apply to all employees involved in decision-making, as well as board members, contractors, and consultants with influence over organizational decisions. High-risk roles (procurement, finance, HR, senior leadership) warrant particular attention, but most effective programs apply disclosure requirements broadly rather than limiting them to senior staff.
What happens after a conflict of interest is disclosed?
The disclosure is reviewed by the appropriate person, typically a compliance officer, line manager, or independent committee depending on the nature of the conflict. The reviewer assesses the risk, decides whether mitigation is needed, and documents the outcome. The person who disclosed should receive a response confirming receipt, the review outcome, and any agreed actions.
How often should conflict of interest disclosures be renewed?
Most organizations run annual renewal cycles, prompting employees to confirm that previously declared interests remain accurate and to identify any new situations. Event-based triggers, role changes, new vendor relationships, promotions, should also prompt a fresh disclosure outside the regular cycle.
What regulations require conflict of interest disclosure?
Requirements vary by jurisdiction and sector. In the EU, the Whistleblowing Directive (2019/1937) requires internal reporting channels for conflicts in public procurement. The UK Bribery Act's adequate procedures defense requires demonstrable controls. Financial services, healthcare, and listed companies face additional sector-specific requirements. Organizations operating across multiple markets should map their obligations by jurisdiction.
