Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Ethics & Conduct

Conflicts Disclosure

Also known as: Conflict of Interest Disclosure, Conflicts of Interest Disclosure, COI Disclosure
Simply put

A conflicts disclosure is a formal process in which an individual reports personal, financial, or professional interests that could improperly influence their judgment or duties. The purpose is to bring potential conflicts into the open so the organization can evaluate and, where needed, manage them. It is commonly used across settings such as corporate boards, research institutions, and public office.

Formal definition

Conflicts disclosure is a governance mechanism requiring covered individuals to declare, typically in a written statement and to the best of their knowledge, any interests, affiliations, activities, or relationships that could create an actual, potential, or perceived conflict of interest with their professional responsibilities. Disclosures often encompass financial, personal, and professional interests, and in some contexts may extend to conflicts of commitment. The declaration is frequently submitted to a designated reviewer or independent committee that assesses the disclosed interests and determines appropriate management measures. Scope, required content, filing frequency, and review procedures vary by organization, sector, and jurisdiction, and specific obligations should be verified against the applicable policy or governing law. This definition addresses the disclosure step and does not detail conflict management, recusal, or resolution processes, which fall outside its scope.

Why it matters

Conflicts disclosure underpins the integrity of decision-making across governance settings. When individuals hold personal, financial, or professional interests that could improperly influence their judgment, undisclosed conflicts can undermine trust in an organization's decisions and expose it to reputational, legal, and operational harm. Bringing such interests into the open is typically the first step that allows an organization to evaluate whether a conflict exists and, where needed, to manage it appropriately.

The mechanism is relevant precisely because a conflict need not be actual to be damaging; potential and perceived conflicts can erode confidence just as effectively. Disclosure creates a documented record that decisions were made with awareness of relevant interests, which supports accountability to boards, regulators, funders, and the public. In research institutions, for example, disclosures made to an independent committee help preserve the credibility of findings; in corporate and public-office settings, they help demonstrate that those in positions of trust are acting in the organization's or the public's interest rather than their own.

Because the specific obligations, required content, and consequences of non-disclosure vary by organization, sector, and jurisdiction, professionals should treat disclosure as one component of a broader conflicts framework rather than a standalone safeguard. Disclosure surfaces interests but does not by itself resolve them; the management, recusal, and resolution steps that follow determine whether a conflict is adequately addressed.

Who it's relevant to

Board members and corporate directors
Directors and senior officers are commonly required to disclose personal, financial, or professional interests that could influence their duties, supporting accountability in board decision-making. The specific obligations depend on the organization's governance policies and applicable law.
Researchers and research institutions
In research settings, individuals may submit a formal declaration of potential conflicts, often to an independent committee, covering financial, personal, and professional interests, and in some cases conflicts of commitment. This helps protect the credibility of research activities.
Public officials and those in public office
Public-sector regimes may require officials to file disclosure statements that interested parties can examine, promoting transparency in public decision-making. The scope and filing requirements are set by the relevant jurisdiction and should be confirmed against governing rules.
Compliance officers and governance professionals
Those responsible for designing and administering conflicts policies rely on disclosure as the entry point to identifying and managing conflicts. They typically define covered individuals, required content, and review routing, and coordinate the separate management and resolution processes that follow disclosure.

Inside Conflicts Disclosure

Personal and Financial Interests
Disclosure of interests held by an individual, such as ownership stakes, investments, board memberships, or other financial relationships, that could reasonably be seen to influence, or appear to influence, the individual's judgment or duties within the organization.
Relationships and Affiliations
Identification of family, personal, or professional relationships (including with vendors, competitors, clients, or other counterparties) that may create an actual, potential, or perceived conflict with the individual's responsibilities.
Outside Activities and Employment
Reporting of secondary employment, consulting engagements, directorships, or other external commitments that could compete with, or divide loyalty from, the individual's obligations to the organization.
Gifts, Hospitality, and Benefits
Declaration of gifts, entertainment, or other benefits received from or offered to parties doing or seeking to do business with the organization, where these could compromise objectivity or create an appearance of impropriety.
Nature of the Conflict
Characterization of whether a disclosed matter represents an actual conflict, a potential conflict, or a perceived conflict, since each is treated differently and the distinction affects the appropriate response.
Timing and Updates
The point at which disclosure is made, commonly at onboarding, on a periodic (often annual) basis, and on an event-driven basis when a new interest or relationship arises, so that the record remains current.
Review and Management Response
The record of how the organization assesses a disclosure and determines any mitigating measures, such as recusal, reassignment, monitoring, or approval, forming part of the governance around the disclosed matter.

Common questions

Answers to the questions practitioners most commonly ask about Conflicts Disclosure.

Is a conflicts disclosure the same as a conflict of interest itself?
No. A conflicts disclosure is the act of reporting a potential, apparent, or actual conflict of interest to the appropriate party; it is not the conflict itself. Disclosing an interest does not by itself create or resolve a conflict. The disclosure is typically the starting point of a process, after which the organization assesses whether a conflict exists and, if so, how it should be managed, mitigated, or avoided. Treating disclosure as the endpoint is a common misconception; in many governance frameworks it is one step within a broader conflicts management process.
Does disclosing a conflict automatically permit the individual to proceed with the related decision or transaction?
Not necessarily. Disclosure alone does not typically authorize an individual to participate in the affected matter. Many governance frameworks and internal policies require additional steps after disclosure, which may include recusal, independent review, or formal approval by a body without the conflict. Whether participation is permitted depends on the nature of the conflict, applicable policies, and, in some cases, legal or regulatory requirements. The specific outcome should be determined under the organization's governing policy and, where relevant, professional or legal advice.
Who should conflicts disclosures typically be made to within an organization?
This varies by organization and by the role of the person disclosing. In many governance structures, disclosures are directed to a designated function such as a compliance office, corporate secretary, general counsel, an ethics committee, or a board committee, depending on the seniority and nature of the interest. Board-level conflicts are often disclosed to the full board or a designated committee, while employee-level conflicts may route through management or a compliance channel. Organizations commonly define the recipient and escalation path in a conflicts of interest policy; the appropriate channel should be confirmed against that policy.
How often should conflicts disclosures be collected or updated?
Practice varies. Many organizations combine a periodic disclosure cycle, such as an annual attestation, with an ongoing obligation to disclose new or changed circumstances as they arise. The rationale is that a point-in-time declaration can become outdated when roles, relationships, or interests change. The appropriate cadence often depends on the organization's risk profile, sector, and regulatory environment. Specific frequency requirements, where they exist, should be verified against applicable regulations and the organization's own policy.
How can an organization document and track conflicts disclosures effectively?
Common approaches include maintaining a register or log that records the disclosure, the assessment performed, any management or mitigation measures applied, and the resulting decision. Documentation typically supports auditability and demonstrates that the disclosure was reviewed rather than merely received. The level of formality often scales with organization size and risk. Beyond noting that a durable, reviewable record is generally regarded as leading practice, the specific tooling or format is a matter of organizational choice and is outside the scope of this definition.
What can be done to encourage complete and timely disclosures?
Factors often cited as supporting disclosure include clear policy definitions of what constitutes a reportable interest, accessible reporting channels, guidance and training so individuals recognize potential conflicts, and a culture in which disclosure is treated as expected rather than as an admission of wrongdoing. Some organizations also address concerns about retaliation. Effectiveness depends on context, and these are general considerations rather than binding requirements; applicability varies by jurisdiction, sector, and organization.

Common misconceptions

Disclosing a conflict resolves it.
Disclosure is typically the first step, not the conclusion. In many governance frameworks the disclosed matter must then be assessed and managed, through recusal, monitoring, or other measures, since disclosure alone does not modify the underlying conflict or its potential effect on objectives.
Only actual conflicts need to be disclosed.
Many policies ask individuals to disclose potential and perceived conflicts as well, because the appearance of a conflict can affect trust and governance even where no actual conflict exists. What must be disclosed depends on the organization's policy and applicable rules, which vary by jurisdiction and sector.
Conflicts disclosure is purely a compliance formality.
While disclosure often supports compliance with policies or regulations, it also serves governance, by informing decision rights and independence, and risk management, by surfacing matters that could affect objectives. It legitimately spans more than one GRC pillar rather than being a standalone paperwork exercise.

Best practices

Maintain a written conflicts of interest policy that defines actual, potential, and perceived conflicts and specifies who must disclose, what must be disclosed, and to whom.
Collect disclosures at multiple points, at onboarding, periodically, and on an event-driven basis, so records stay current as interests and relationships change.
Separate the act of disclosing from the act of managing, ensuring each disclosed matter is reviewed and, where warranted, addressed through measures such as recusal, reassignment, or monitoring.
Assign an independent reviewer or committee to assess disclosures, avoiding situations where individuals evaluate their own conflicts.
Document the assessment and any mitigating actions taken, retaining an auditable record that supports accountability and later review.
Communicate expectations and provide periodic training so individuals understand what to disclose and why, recognizing that specific obligations vary by jurisdiction, sector, and organization and may require professional advice.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.