Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Ethics & Conduct

Business Conduct Standards

Also known as: Code of Business Conduct, Code of Business Conduct and Ethics, Standards of Business Conduct, Corporate Standard of Business Conduct
Simply put

Business conduct standards are the rules and principles an organization sets to guide how its people behave when doing business, covering matters such as ethics, legal compliance, and responsible dealing with others. They typically apply to employees, directors, and sometimes business partners, and describe the values the organization expects them to uphold. In some contexts, the term also refers to specific conduct rules imposed by regulators on particular types of firms.

Formal definition

Business conduct standards generally denote a set of organizational rules, principles, and expected practices addressing organizational values, ethics, and legal compliance, commonly articulated in a document such as a Code of Business Conduct and Ethics. In a governance and compliance context, such standards are internal policy instruments that define expected behavior for covered persons, often employees, board members, and, where specified, business partners, and support adherence to applicable laws and internal policy. The term also carries a distinct, jurisdiction-specific regulatory meaning: for example, the U.S. Securities and Exchange Commission has adopted 'Business Conduct Standards' as binding rules for security-based swap dealers and major security-based swap participants implementing provisions of Title VII of the Dodd-Frank Act. Practitioners should therefore distinguish between voluntary, organization-authored conduct codes (a matter of internal policy and leading practice) and named statutory or regulatory conduct standards (binding legal requirements whose scope and applicability depend on sector and jurisdiction); the precise obligations in the latter case should be verified against the primary regulatory source.

Why it matters

Business conduct standards translate an organization's stated values into concrete behavioral expectations, giving employees, directors, and in many cases business partners a reference point for how to act when facing ethical or legal questions. Without such standards, expectations remain implicit and inconsistently applied, which can weaken accountability and make it harder to demonstrate that an organization takes ethics and legal compliance seriously. As one publicly available example illustrates, a company may state that it is a professional, responsible, and law-abiding entity and devote considerable time and expense to conducting business accordingly, language that signals how conduct standards are used to articulate organizational commitments.

The term matters for a second, distinct reason: it can carry a binding regulatory meaning in specific sectors. The U.S. Securities and Exchange Commission has adopted 'Business Conduct Standards' as rules for security-based swap dealers and major security-based swap participants, intended to implement provisions of Title VII of the Dodd-Frank Act. Because the same term describes both voluntary, organization-authored conduct codes and named statutory obligations, practitioners must be careful not to conflate the two. Misreading a leading-practice conduct code as a legal mandate, or overlooking a genuine regulatory conduct standard, can create either false comfort or unaddressed exposure.

For GRC professionals, the practical significance lies in this dual nature. Internal conduct standards are policy instruments that support, but do not themselves guarantee, compliance with applicable law; their effectiveness depends on how they are communicated, monitored, and enforced. Where a named regulatory standard applies, the precise obligations, scope, and applicability turn on sector and jurisdiction and should be verified against the primary regulatory source rather than assumed from the label alone.

Who it's relevant to

Compliance officers
Compliance functions typically own the drafting, communication, and monitoring of internal conduct codes and are responsible for distinguishing voluntary conduct standards from any binding regulatory conduct standards that apply to the organization's sector. They should verify the scope of covered persons and, where a named regulatory standard exists, confirm obligations against the primary source.
Boards of directors and governance professionals
Directors are commonly among the covered persons under a Code of Business Conduct and Ethics and often oversee its adoption and review. Governance professionals use conduct standards to articulate organizational values and expected behavior, reinforcing accountability structures.
General counsel and legal teams
Legal teams assess where the term carries binding meaning, such as the SEC's Business Conduct Standards for security-based swap dealers and major security-based swap participants under Title VII of the Dodd-Frank Act, and advise on applicability, which varies by sector and jurisdiction and may require interpretation against the primary regulatory source.
Employees and business partners
Conduct standards frequently apply not only to employees but also to business partners where the standard so specifies, setting expectations for ethical, responsible, and law-abiding dealing. Covered persons rely on these standards as a reference point for expected behavior in day-to-day business.
Firms in regulated sectors such as security-based swaps
Entities classified as security-based swap dealers or major security-based swap participants are subject to the SEC's named Business Conduct Standards and must treat them as legal requirements rather than voluntary guidance, verifying precise obligations against the applicable rules.

Inside Business Conduct Standards

Code of Conduct
A foundational document that articulates the organization's expectations for ethical behavior and integrity, typically covering how employees, officers, and often third parties should act in the course of business. It commonly serves as the reference point from which more detailed conduct policies flow.
Conflicts of Interest Provisions
Guidance addressing situations where personal, financial, or other interests could improperly influence, or appear to influence, an individual's professional judgment. Such provisions typically set out disclosure expectations and escalation routes rather than prescribing a single universal rule.
Anti-Bribery and Anti-Corruption Expectations
Standards addressing the giving or receiving of improper payments, gifts, or advantages. Applicability and specific obligations vary by jurisdiction and sector, and these expectations often reference external legal requirements that should be verified against the applicable primary sources.
Fair Dealing and Market Conduct
Expectations governing honest and fair treatment of customers, suppliers, competitors, and other stakeholders. This element spans compliance (adherence to applicable market and consumer-protection laws) and governance (the organization's chosen ethical posture).
Reporting and Escalation Mechanisms
Channels through which individuals can raise concerns about suspected misconduct, often including protections against retaliation. These mechanisms typically connect the standards to the organization's broader compliance and oversight structures.
Governance and Accountability Structure
The roles, decision rights, and oversight responsibilities, such as those of the board, senior management, and compliance function, that direct how the standards are set, maintained, and enforced. This element reflects the governance pillar rather than compliance alone.
Consequences and Enforcement
A statement of how breaches are handled, which may range from remediation to disciplinary action. The specific measures depend on the organization, applicable employment law, and jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Business Conduct Standards.

Are business conduct standards the same as a company's compliance program?
Not exactly. Business conduct standards typically articulate the ethical principles and behavioral expectations an organization sets for its people, whereas a compliance program is the broader set of structures, controls, training, monitoring, and remediation activities designed to promote adherence to laws, regulations, and internal policies. Conduct standards often sit within, and inform, a compliance program, but they are one input rather than the whole. The two also span different pillars: conduct standards touch governance (setting expectations and tone) and compliance (adherence), while the surrounding program is largely a compliance and risk-management apparatus. The precise relationship varies by organization.
Does adopting formal business conduct standards guarantee ethical behavior or legal compliance?
No. Written standards can establish expectations and provide a reference point for accountability, but they do not by themselves ensure that individuals behave ethically or that the organization remains compliant. Standards are one control among many, and their effectiveness depends on factors such as communication, training, incentives, leadership example, monitoring, and enforcement. No document or control can be said to eliminate misconduct risk or guarantee an outcome. Framing standards as a guarantee tends to overstate what they can achieve on their own.
How do business conduct standards typically relate to a separate code of conduct or code of ethics?
In many organizations the terms overlap and are used interchangeably, though usage is not standardized. A code of conduct is often the formal document that expresses the organization's business conduct standards, while a code of ethics may emphasize underlying values and principles. Some organizations maintain a single combined document; others separate high-level ethical principles from more detailed behavioral rules. Because these labels carry no universally fixed meaning, professionals should confirm how a given organization defines and structures each document rather than assuming a fixed hierarchy.
Who is typically responsible for owning and maintaining business conduct standards?
Ownership arrangements vary by organization size, sector, and governance structure. Responsibility for approving and overseeing standards commonly rests with the board or a board committee as a governance matter, while day-to-day maintenance is often assigned to a compliance, ethics, legal, or human resources function. Larger organizations may designate a chief compliance or ethics officer. Clarifying decision rights, review cadence, and escalation paths is generally regarded as leading practice rather than a universal legal requirement, and specific expectations differ across jurisdictions and regulatory regimes.
How often should business conduct standards be reviewed and updated?
There is no single mandated review frequency that applies across all organizations. Many organizations review standards periodically, such as on an annual or multi-year cycle, and also on a triggered basis when significant changes occur, for example in applicable laws, business activities, jurisdictions of operation, or following an incident. The appropriate cadence depends on the organization's risk profile and regulatory environment. Any specific frequency expectations should be verified against applicable regulations, listing rules, or sector guidance, some of which may impose their own requirements.
How can an organization assess whether its business conduct standards are actually effective?
Effectiveness is typically evaluated using a combination of indicators rather than any single measure. Common approaches include monitoring training completion and comprehension, tracking use of reporting or whistleblowing channels, reviewing investigation and disciplinary outcomes, conducting culture or ethics surveys, and internal audit assessments. These measures provide evidence about awareness and application but should be interpreted with care, since metrics can be imperfect proxies for actual behavior. Assessment methods and any regulatory expectations vary by context, and no set of indicators can conclusively confirm that standards are working.

Common misconceptions

Business conduct standards are purely a compliance matter about following the law.
While the standards often incorporate legal obligations, they typically span more than one pillar: governance sets the structures and decision rights that establish and oversee the standards, and the standards frequently articulate ethical expectations that go beyond the minimum required by binding law. Treating them as compliance-only overlooks the governance and cultural dimensions.
Having a written code of conduct ensures that misconduct will not occur.
A documented standard is a control that can modify risk, but no control eliminates the underlying risk. The presence of standards does not guarantee compliant behavior; effectiveness depends on communication, oversight, escalation mechanisms, and enforcement, and residual risk typically remains.
The same business conduct standards apply uniformly to every organization.
Applicability and content vary by jurisdiction, sector, and organization size. Some elements reflect binding legal requirements while others reflect voluntary leading practice or organizational choice, so standards should be tailored and validated against the primary sources relevant to the specific context.

Best practices

Distinguish clearly within the standards between binding legal obligations and voluntary ethical commitments, so readers understand what is required by law versus what reflects organizational choice or leading practice.
Assign explicit governance roles and decision rights for setting, maintaining, and overseeing the standards, connecting them to board and senior management accountability rather than treating them as a standalone document.
Provide accessible reporting and escalation channels, together with protection against retaliation, and ensure they link to the organization's broader oversight and compliance structures.
Tailor the standards to the organization's jurisdictions, sectors, and size, and verify any referenced legal requirements against the applicable primary sources rather than assuming uniform applicability.
Review and update the standards periodically to reflect changes in applicable law, regulatory expectations, and evolving framework language, noting that such guidance changes over time.
Reinforce the standards through communication, training, and consistent enforcement, recognizing that documentation alone modifies but does not eliminate conduct-related risk.
Promotional banner for the Penetration Report Template Kit