How to handle conflicts of interest: a step-by-step guide for compliance teams
A conflict of interest isn't always a problem, but handling it poorly turns a minor risk into a real one. This guide walks through five steps for assessing, mitigating, documenting, and escalating conflicts of interest, plus the mistakes that most often derail the process.
A conflict of interest is not always a problem. An undisclosed conflict of interest almost always is.
The distinction matters because how your organization handles COI determines whether it is a managed governance process or an unmanaged liability. Most of the reputational and legal damage from COI situations does not come from the conflict itself. It comes from what happened, or did not happen, after someone identified it. Poor handling compounds the original risk; consistent handling reduces it.
This guide covers the practical steps for handling conflicts of interest once they surface, the mitigation options available, and when to escalate.
Step 1: Surface the conflict early
You cannot handle a conflict you do not know about. The first job is making it easy for employees to raise potential conflicts before they become active risks, not after they have already shaped a decision.
That means a clear, accessible conflict of interest disclosure process that employees trust and know how to use. It means a culture that treats disclosure as normal professional practice, not an implicit admission that something has gone wrong. And it means proactive prompts at onboarding, at annual renewal, and when employees move into roles with higher exposure.
The most effective COI programs collect disclosures early and routinely. They do not rely on employees to self-identify in the moment of a difficult decision. For a detailed breakdown of the situations that require disclosure, see our guide to common examples of conflict of interest in the workplace.
Step 2: Assess the conflict
Once a conflict is disclosed, assess it. Not all conflicts carry the same risk, and proportionate assessment is what keeps the process sustainable without creating disproportionate burden for low-risk disclosures.
A sound assessment covers four questions.
Is the conflict actual, potential, or perceived? An actual conflict is one that is currently influencing a decision. A potential conflict exists but has not yet affected any decision. A perceived conflict is one that a reasonable observer could conclude might be affecting decisions, even if it is not. All three require attention, but the urgency and depth of the response differ.
What is the employee's decision-making proximity? Risk is higher when the employee is directly involved in a decision where the conflict is relevant: approving a vendor contract, conducting a performance review, selecting a procurement shortlist. Indirect involvement or no direct decision-making authority reduces the risk profile.
What is the materiality of the interest? A minor financial interest in a company your organization does business with is a different risk level from a significant ownership stake. A historic personal relationship with no current bearing on work is different from an active personal relationship that intersects directly with reporting lines.
Are existing controls already managing the risk? In some cases, organizational safeguards already in place (committee sign-off requirements, dual-approval processes, independent review) may already manage the risk the conflict creates. If so, the assessment outcome may simply be to document that fact and set a review date.
Document every assessment: what was disclosed, who assessed it, what the risk evaluation concluded, and what action was taken. Without this record, you cannot demonstrate that a conflict was handled appropriately if the question is ever raised later.
Step 3: Choose the right mitigation
Mitigation should be proportionate to the risk. The goal is to manage the conflict, not to penalize the person who disclosed it. An overly severe response to a low-risk disclosure discourages future disclosures from everyone who hears about it.
The most common mitigation options, in order of increasing restriction:
Documentation and monitoring. For low-risk potential conflicts, document the disclosure, note the assessment outcome, and set a review date. No further action required beyond the record.
Recusal from relevant decisions. The most commonly applied control. The employee steps back from specific decisions where the conflict is relevant while continuing all other aspects of their role. For example: a procurement officer with a personal relationship with a supplier's representative is excluded from any evaluation, selection, or contract management involving that supplier.
Independent review or committee sign-off. Rather than full recusal, a second independent reviewer must approve any decision involving the conflicted interest. This keeps the employee involved but adds an oversight layer that removes the decision from their sole authority.
Reporting-line or role changes. Where the conflict runs through a reporting relationship (a manager supervising a family member or romantic partner, for instance), restructuring the reporting line removes the direct conflict. More disruptive, but sometimes the most practical option.
Divestment or termination of the outside interest. For financial conflicts involving significant ownership stakes, the cleanest resolution is for the employee to divest from the interest that creates the conflict. This is the most appropriate mitigation for senior leaders or board members, where the scale of decision-making authority makes other controls insufficient.
Prohibition. Where the conflict cannot be managed by any other means (concurrent employment with a direct competitor being the clearest example), prohibiting the conflicting activity may be the only workable option.
Communicate the agreed mitigation clearly to the employee, to relevant managers, and to anyone who needs to know to implement it. The goal is to manage the conflict, not to broadcast it, so protect confidentiality throughout.
Step 4: Document and maintain the record
A conflict that is managed but undocumented is difficult to defend. When questions arise about how a decision was made, or whether a particular relationship was ever assessed, the audit trail is what lets your team answer them clearly.
The record should capture: what was disclosed; when; who assessed it; the risk assessment outcome; what mitigation was agreed and when it takes effect; who is responsible for implementing it; and the review date. It does not need to be lengthy, but it does need to be complete, centrally stored, and accessible to authorized reviewers.
Manual tracking through shared inboxes and spreadsheets creates gaps. Disclosures get missed. Mitigation actions are agreed verbally but never recorded. Review dates pass without follow-up. These are the gaps that turn a handled conflict into an undocumented liability. A conflict of interest management platform creates the audit trail automatically, tracks mitigation actions to completion, and surfaces upcoming review dates before they lapse.
Step 5: Monitor and review
Conflicts change. The supplier relationship that posed low risk a year ago may now sit at the center of a major procurement decision. The personal relationship that triggered a reporting-line adjustment may have ended. The outside board seat disclosed as a minor matter may have become strategically significant.
Build in review triggers: a set date for periodic reassessment, and event-based triggers for earlier review. A role change, a new project, a vendor that grows from a minor supplier to a major contract partner: any of these should prompt a fresh look at whether the original mitigation still holds.
Annual renewal cycles, where employees confirm that previously disclosed interests remain accurate and identify any new situations, are the minimum. The organizations that handle COI most effectively treat the register of disclosed conflicts as a live document, not a historical archive.
When to escalate
Most conflicts can be handled by compliance or HR with standard assessment and mitigation. Some require escalation.
Escalate to legal counsel when the conflict involves potential regulatory breach, when the mitigation decision has significant legal or contractual implications, or when the employee contests the assessment.
Escalate to senior leadership or the board when the conflict involves a member of the executive team or board, when the financial materiality is significant, or when the conflict is connected to an active investigation.
Escalate to external counsel when your organization operates in a regulated sector with specific COI disclosure requirements, or when the conflict has potentially crossed into fraud, bribery, or other criminal territory.
Document every escalation decision and its outcome with the same rigor as the original disclosure. The escalation record is part of the same audit trail.
The common mistakes that make handling harder
Treating every conflict identically. A one-size-fits-all response overburdens low-risk situations and may under-respond to high-risk ones. Proportionality is not optional.
Focusing on the conflict without closing the loop. Employees who disclose and never hear back draw their own conclusions. Consistent follow-up, even when the answer is that no further action is needed, builds the trust that makes future disclosures more likely.
Applying mitigation without tracking it. An agreed recusal that is never enforced is not mitigation. It is a documented decision that was not implemented. Mitigation needs owners, deadlines, and a review process.
Ignoring perceived conflicts. Actual conflicts cause obvious problems. Perceived conflicts cause subtler but equally significant ones. A decision genuinely unaffected by a personal interest but that a reasonable observer could question still carries reputational and trust risk. The handling process applies to all three categories.
How SpeakUp Paths supports conflict handling
Compliance teams managing COI across multiple regions, roles, and regulatory requirements need a process that runs the same way every time, regardless of who receives the disclosure.
With SpeakUp Paths, your team works from a structured workflow that makes each step repeatable and documentable. Disclosures arrive through a purpose-built intake form and route automatically to the right reviewer based on configurable logic. Assessment and mitigation outcomes land in a centralized audit trail. Mitigation actions track to completion. Renewal cycles run through automated campaigns.
See how the hidden risks in manual disclosure programs compound over time, and how a structured platform changes the risk profile. Or book a demo to see SpeakUp Paths in action.
FAQ
What is the first step in handling a conflict of interest?
Surface it early. The handling process only starts when a conflict is disclosed, which is why making disclosure easy, trusted, and routine is the foundation of effective COI management. A conflict that is never disclosed cannot be assessed or mitigated.
What are the mitigation options for a conflict of interest?
Six options cover most situations: documentation and monitoring for low-risk potential conflicts; recusal from relevant decisions; independent review or committee sign-off; reporting-line changes; divestment of the financial interest; and, where the conflict cannot otherwise be managed, prohibition of the conflicting activity. The right choice depends on the risk level, the nature of the conflict, and the employee's role.
When should a conflict of interest be escalated?
Escalate to legal counsel when regulatory breach is possible, when the decision has significant legal implications, or when the employee contests the assessment. Escalate to senior leadership or the board when the conflict involves executive or board members, or when the financial materiality is significant.
How should conflicts of interest be documented?
Capture what was disclosed, when, who assessed it, the risk assessment outcome, what mitigation was agreed, who is responsible for implementing it, and the review date. This documentation should be centralized, complete, and accessible to authorized reviewers.
How often should disclosed conflicts be reviewed?
At minimum, annually, through a renewal cycle where employees confirm that previously disclosed interests remain accurate. Event-based reviews should also trigger on role changes, new vendor relationships, or any material change in the circumstances that created the original conflict.
