Our Code of Conduct
The principles that guide our decisions and conduct across advisory, training and software.
Explore 19 risk areas ↓Download the PDF ↓Our standards begin with us.
We established Compliance House to help organisations make integrity and compliance part of everyday decisions. That responsibility begins with our own conduct.
Our advice must be honest, independent and grounded in evidence. Commercial pressure never justifies changing findings, concealing risks or overstating our capabilities. Sometimes the right decision is to decline an engagement or pause work already underway.
I ask every colleague to seek guidance when uncertain and speak up when something seems wrong. Leaders must listen and protect people who raise concerns from retaliation. This Code is our commitment to practise the standards we recommend to others.
Who this Code applies to
It applies to our founder, leaders and employees. We expect instructors, consultants, contractors and others acting for us to follow the requirements relevant to their work.
Follow applicable law and contractual duties. Seek advice where requirements conflict; apply a stricter internal standard where lawful. Internal approval cannot authorise unlawful conduct.
Before you decide
Is it lawful? Does it protect our independence? Is it supported by evidence? Does it protect people and information? Can I explain the decision openly?
If you are unsure, pause and seek guidance.
Risk areas and expected conduct
One policy, five dos and five don’ts for every area.
01Anti-bribery and corruption
Our policy
We prohibit bribery, kickbacks and facilitation payments, directly or through others, in public and private business.
Our work can involve procurement teams, public officials, referral partners and decision-makers whose choices affect our business. No commercial opportunity justifies offering, requesting or accepting an improper advantage, whether money, employment, a personal favour or another benefit. This applies equally to payments made by someone acting for us. Fees must reflect legitimate services and be supported by clear records. Where a demand or arrangement raises concern, we pause the transaction, seek guidance and document the response. A threat to personal safety requires a safety-first response followed by reporting as soon as it is safe.
Do
- Check the purpose of every payment.
- Verify recipients and supporting records.
- Escalate demands for unofficial payments.
- Record interactions with public officials accurately.
- Prioritise safety under threats and report when safe.
Don’t
- Offer anything to influence a decision improperly.
- Accept a kickback for a referral or purchase.
- Use an intermediary to make a prohibited payment.
- Disguise bribes as consulting fees or donations.
- Treat customary practice as permission to pay.
02Gifts, hospitality and expenses
Our policy
Business courtesies must be modest, transparent, lawful and free from any expectation of preferential treatment.
Hospitality can support a professional relationship, but it can also create an obligation or the appearance of influence. We assess the purpose, value, frequency, timing and participants together, including whether a tender, selection or assessment is underway. An offer that seems modest in isolation may be inappropriate when repeated or extended to relatives. We follow the recipient’s restrictions as well as our own approval requirements. Expenses must have a genuine business purpose, and declining an inappropriate offer must never disadvantage the person who raises the concern.
Do
- Check both our rules and the recipient’s rules.
- Seek approval before sensitive or unusual hospitality.
- Record the value, recipient and business purpose.
- Decline offers that could compromise your judgment.
- Submit accurate receipts for legitimate expenses.
Don’t
- Give or accept cash or cash equivalents as gifts.
- Offer hospitality to influence a tender or review.
- Split expenses to bypass approval.
- Charge personal entertainment to a client.
- Assume an invitation is acceptable because it is reciprocal.
03Conflicts of interest and independence
Our policy
We disclose and manage actual, potential and perceived conflicts before they affect advice, procurement or client acceptance.
Clients rely on us to exercise judgment without hidden loyalties. Personal relationships, investments, outside work, referral arrangements and software sales incentives can all affect that judgment or how it is perceived. Disclosure is therefore required before participation in a relevant decision, not only after a conflict causes harm. We assess whether the conflict can be managed through separation of responsibilities, independent review or appropriate disclosure and consent. Consent alone does not make every conflict acceptable. If credible safeguards cannot protect independent judgment and confidentiality, we decline or end the affected work.
Do
- Disclose relevant financial and personal interests.
- Check conflicts before accepting an engagement.
- Step back from decisions involving connected parties.
- Document safeguards and necessary client disclosures.
- Update disclosures when circumstances change.
Don’t
- Hide an outside role or competing interest.
- Recommend software because of an undisclosed incentive.
- Review your own work as if independently assured.
- Favour relatives or friends in commercial decisions.
- Use client relationships for undisclosed personal gain.
04Professional quality and truthful claims
Our policy
Our advice, training and software claims must be evidence-based, within our competence and clear about their limitations.
Our reputation depends on whether clients can use our work to make sound decisions. We define the question being addressed, the evidence available and the boundaries of each engagement. Advice must reflect the client’s circumstances rather than simply repeat a template. Training must have relevant learning objectives, and software must be described according to its tested capabilities. We distinguish legal requirements, professional judgment and illustrative guidance. Significant limitations and contrary evidence belong in our conclusions. Where specialist competence is needed, we obtain it rather than imply expertise we do not possess.
Do
- Agree scope, deliverables and responsibilities in writing.
- Verify sources and distinguish facts from assumptions.
- Use qualified reviewers for material deliverables.
- Explain tool scores, uncertainty and limitations.
- Correct material errors and inform affected clients.
Don’t
- Guarantee certification or regulatory approval.
- Present self-assessment as independent certification.
- Invent credentials, findings or client endorsements.
- Omit adverse findings to preserve a sale.
- Accept work beyond competence without suitable support.
05Fraud, financial integrity and tax
Our policy
We maintain complete, accurate records and prohibit fraud, false billing, asset misuse and assistance with tax evasion.
Financial integrity includes how we propose, deliver, record and charge for our services. Clients and colleagues must be able to trace charges to agreed work and understand who approved a commitment. We separate preparation and approval where practicable, review exceptions and retain evidence sufficient to explain transactions. Performance targets must not encourage inflated hours, misleading revenue recognition or concealed liabilities. Company resources are entrusted to us for authorised purposes. Suspected fraud requires careful preservation of records and appropriate review, not informal adjustments that hide the underlying issue.
Do
- Record time, expenses and revenue accurately.
- Follow delegated approval limits.
- Reconcile invoices with agreed services.
- Preserve reliable accounting and tax records.
- Report unexplained transactions or discrepancies.
Don’t
- Bill for work not performed.
- Alter receipts, dates or performance records.
- Create undisclosed accounts or off-book funds.
- Use company or client assets for unauthorised purposes.
- Help conceal income or falsify tax information.
06Money laundering and illicit finance
Our policy
We seek to understand who we work with and reject arrangements that disguise criminal proceeds or illicit funding.
Professional services can be misused to lend credibility to questionable entities or to explain movements of funds that lack a genuine commercial basis. Our checks therefore consider ownership, the nature of the requested work, payment arrangements and inconsistencies in the information supplied. The depth of review should reflect the risk and applicable obligations; it is not a claim that every engagement is subject to identical regulated-sector duties. We do not proceed merely because payment is available or a client is well known. Unresolved concerns require escalation and, where necessary, refusal or lawful reporting.
Do
- Verify client identity and relevant ownership information.
- Understand the commercial purpose of engagements.
- Check unusual payment sources and refund requests.
- Escalate concerns before proceeding.
- Follow applicable reporting requirements with specialist advice.
Don’t
- Accept unexplained third-party payments.
- Return funds to unrelated accounts without verification.
- Structure transactions to evade checks.
- Provide services to conceal illicit ownership or funds.
- Warn subjects of a confidential inquiry where disclosure is prohibited.
07Sanctions and cross-border trade
Our policy
We assess applicable sanctions, export controls and cross-border restrictions before providing services, software or technical assistance.
Cross-border exposure may arise through client ownership, connected banks, technology access, subcontractors or the eventual use of our advice. We examine the restrictions relevant to the jurisdictions and activities involved rather than assume one screening list provides a complete answer. Controls must consider indirect ownership, service restrictions and changes during the engagement. A request to remove a country reference or introduce an unexplained intermediary is a reason for further review. We do not design structures to evade restrictions or give assurance beyond the facts and specialist analysis available.
Do
- Check parties, ownership, destinations and end use.
- Reassess exposure when facts or restrictions change.
- Seek specialist advice on uncertain restrictions.
- Document checks and required authorisations.
- Pause potentially restricted work pending review.
Don’t
- Rely only on a name-screening result.
- Use intermediaries to evade restrictions.
- Conceal destinations, owners or end users.
- Assume advisory services are always exempt.
- Promise a transaction is lawful without adequate review.
08Fair competition and market conduct
Our policy
We compete on quality and value, safeguard competitively sensitive information and prohibit collusion and misuse of inside information.
We may meet competitors through conferences, professional networks, partnerships and joint proposals. These settings do not justify sharing information that reduces independent competition. We distinguish legitimate collaboration from arrangements that coordinate prices, customers or bidding behaviour, and seek review where the boundary is unclear. Information obtained through client work must not become an advantage in personal trading or another engagement. Confidentiality continues after the project ends. When a discussion becomes improper, silence is not sufficient: we make our objection clear, leave where appropriate and report the incident.
Do
- Set prices and commercial terms independently.
- Use legitimate sources for market research.
- Leave and report improper competitor discussions.
- Protect non-public information about client transactions.
- Review joint bids and collaborations for competition risk.
Don’t
- Agree prices, bid outcomes or customer allocation with competitors.
- Exchange future pricing or confidential strategies.
- Obtain competitor secrets through deception.
- Trade securities using inside information.
- Tip others about confidential market-sensitive developments.
09Third parties and responsible procurement
Our policy
We select and monitor partners, instructors, suppliers and subcontractors using proportionate integrity and capability checks.
Others who represent us can affect our clients and reputation as directly as our own employees. Selection must therefore consider integrity, competence, security and the ability to meet agreed standards, not price alone. We apply checks proportionate to the service and exposure, set clear contractual expectations and review material changes over time. Outsourcing does not transfer away our responsibility to exercise oversight. Where concerns arise, we evaluate the severity, available remedies and consequences of continuing the relationship, documenting why corrective action, suspension or termination is appropriate.
Do
- Assess risk before onboarding a provider.
- Verify qualifications, ownership and references where relevant.
- Include confidentiality and conduct requirements in contracts.
- Monitor performance and significant changes.
- Address concerns through corrective action or disengagement.
Don’t
- Outsource prohibited conduct.
- Skip checks because a supplier is recommended by a client.
- Accept unexplained fees or vague deliverables.
- Allow unauthorised subcontracting or data access.
- Ignore credible misconduct because replacement is inconvenient.
10Confidentiality and personal data
Our policy
We protect client and personal information throughout its lifecycle and use it only for authorised, lawful purposes.
Compliance work can reveal allegations, employee details, commercial strategies and sensitive evidence. Access to that information is a responsibility, not permission to use it freely. We define the purpose of collection, limit what we request and establish appropriate access, retention and disposal arrangements. Client material must remain separated where necessary, including in demonstrations and training. Personal data rights and contractual confidentiality both require attention. Before sharing information with a platform, supplier or another country, we check the relevant safeguards and authorisations. Suspected exposure is escalated promptly so that containment and any required notifications can be assessed.
Do
- Collect only information necessary for the task.
- Confirm the lawful basis and required notices.
- Restrict access to people with a business need.
- Use approved storage, transfer and deletion methods.
- Report suspected data exposure promptly.
Don’t
- Reuse client data for another engagement without authorisation.
- Publish client names, logos or cases without permission.
- Discuss confidential matters in public places.
- Keep personal data indefinitely for convenience.
- Transfer data across borders without checking requirements.
11Cybersecurity and software integrity
Our policy
We protect systems and client evidence through secure access, careful development and prompt incident response.
Our websites, tools and document-sharing arrangements must be designed around the information they handle and the harm that unauthorised access could cause. Security involves clear permissions, secure configuration, tested recovery arrangements and careful management of changes. A feature is not ready simply because it functions in a demonstration. We consider how it behaves with real client information, errors and misuse. Suppliers and integrations require similar scrutiny. When an incident occurs, the priority is containment, preservation of relevant evidence and coordinated communication, rather than hiding the issue or making unverified assurances.
Do
- Use strong unique credentials and multifactor authentication.
- Keep approved devices and software updated.
- Test access controls, backups and relevant security measures.
- Review software changes before release.
- Report phishing, lost devices and vulnerabilities promptly.
Don’t
- Share passwords or access tokens.
- Store confidential evidence in publicly accessible folders.
- Disable security controls for convenience.
- Install unapproved software or use untrusted devices for client work.
- Hide a breach or promise absolute security.
12Responsible artificial intelligence
Our policy
We use AI with human accountability, appropriate data safeguards and verification proportionate to the consequences of its use.
AI can assist research, drafting, analysis and software development, but it does not carry our professional responsibility. We assess each use by its impact on people, confidentiality and the reliability of the resulting advice. Review must be substantive: a person approving an output must be able to challenge its sources, logic and conclusions. We consider provider data practices, intellectual property, bias and the need to explain AI-supported work to clients. Where adequate verification or safeguards are unavailable, we limit or avoid the use. Efficiency never justifies presenting uncertain machine-generated content as established fact.
Do
- Use approved AI tools for defined purposes.
- Verify generated facts, citations and recommendations.
- Check outputs for bias and unfair effects.
- Keep a qualified person responsible for material decisions.
- Explain material AI use and limitations when relevant.
Don’t
- Upload confidential data to an unapproved model.
- Present fabricated sources as verified research.
- Delegate consequential judgments entirely to AI.
- Generate deceptive impersonations or endorsements.
- Assume AI output is lawful, accurate or owned by us.
13Human rights and labour standards
Our policy
We respect human rights and seek to prevent, address and avoid contributing to abuses in our operations and business relationships.
Human rights considerations extend beyond our own workplace to the clients, suppliers and activities with which our services are connected. We pay attention to vulnerable people and to circumstances in which our work could enable, legitimise or conceal harm. Reviews should consider the severity of potential impacts, not only the commercial risk to Compliance House. Where we identify concerns, we use the influence available to prevent or reduce harm and assess appropriate remedy. Disengagement decisions must also consider their effects on people. We do not treat contractual assurances as a substitute for examining credible evidence of abuse.
Do
- Consider human rights impacts in client and supplier reviews.
- Check for forced labour, child labour and exploitation risks.
- Respect lawful worker representation and association.
- Listen to affected people and escalate credible concerns.
- Support appropriate remedy where we cause or contribute to harm.
Don’t
- Retain identity documents to restrict a worker’s freedom.
- Tolerate coercion, trafficking or exploitative recruitment fees.
- Ignore abuse because it occurs at a subcontractor.
- Obstruct legitimate worker concerns or representation.
- Provide advice intended to conceal human rights abuses.
14Respect, inclusion and fair employment
Our policy
We maintain a respectful workplace and learning environment, free from discrimination, harassment, bullying and retaliation.
Respectful conduct is required in offices, client premises, training sessions, travel and digital communications. Seniority, commercial importance or a successful track record does not excuse intimidation or exclusion. We aim to make opportunities and participation accessible through fair criteria and reasonable adjustments. Managers must respond to concerns without blaming the person affected or assuming that informal behaviour is harmless. Complaints require attention to dignity, fairness and the rights of everyone involved. A person should be able to disagree professionally, ask for help or report inappropriate conduct without fear of losing opportunities.
Do
- Base recruitment and advancement on relevant merit.
- Use respectful language in person and online.
- Consider reasonable accessibility and accommodation needs.
- Intervene safely or seek support when misconduct occurs.
- Handle complaints fairly and sensitively.
Don’t
- Discriminate on personal characteristics unrelated to the role.
- Make unwanted sexual comments, advances or contact.
- Humiliate colleagues, clients or training participants.
- Exclude people as punishment for raising concerns.
- Dismiss abusive behaviour as humour or commercial pressure.
15Health, safety and wellbeing
Our policy
We plan work, travel and events to protect physical and psychological wellbeing and prevent avoidable harm.
Our work may involve intensive deadlines, remote working, travel and unfamiliar client locations. We assess these conditions before they create avoidable harm, including fatigue, isolation and psychological pressure. Everyone has a responsibility to follow relevant precautions and raise concerns, while leaders must provide realistic workloads and respond to unsafe conditions. Client deadlines do not override safety. Incident and near-miss reporting is used to learn and improve, not to discourage disclosure. Where specialist or emergency support is needed, obtaining that support takes priority over maintaining the appearance of uninterrupted service.
Do
- Assess risks before travel and on-site activities.
- Follow venue safety and emergency procedures.
- Report hazards, incidents and near misses.
- Manage workload and fatigue responsibly.
- Stop unsafe work and seek assistance.
Don’t
- Pressure anyone to continue in unsafe conditions.
- Work or drive while impaired.
- Ignore signs of severe stress or exhaustion.
- Block exits or bypass safety instructions.
- Conceal injuries or discourage incident reporting.
16Environment and responsible resource use
Our policy
We seek to reduce the environmental impact of our operations and make environmental claims only when supported by evidence.
Although our services are primarily knowledge-based, travel, digital infrastructure, equipment and purchasing have environmental consequences. We consider practical ways to reduce avoidable consumption without shifting impacts out of sight. Decisions should take account of the useful life and responsible disposal of equipment as well as immediate cost. Environmental reporting must distinguish measured results, estimates and aspirations. We avoid overstating the effect of individual actions or suppliers’ claims. Where we advise clients on environmental matters, we stay within our competence and communicate the evidence and limitations behind our conclusions.
Do
- Consider lower-impact travel and meeting options.
- Reduce avoidable energy, paper and material use.
- Dispose of electronic equipment through suitable channels.
- Consider environmental practices when choosing suppliers.
- Keep evidence for environmental performance statements.
Don’t
- Make unsupported carbon-neutral or sustainability claims.
- Dispose of batteries or devices with confidential data carelessly.
- Hide adverse environmental impacts in reports.
- Treat offsets as a substitute for examining actual impacts.
- Misrepresent estimates as measured results.
17Intellectual property and public communications
Our policy
We respect ownership and licensing rights and communicate accurately about our work, clients and capabilities.
Our materials combine original work with sources, standards, software and images that may carry separate rights. We establish what may be used, adapted, shared or sold before incorporating it into a deliverable. Attribution does not replace a required licence or permission. Public communication must accurately describe our experience, certifications and relationships, including on social media and in demonstrations. Approval to work for a client is not automatically approval to publicise that relationship. When an error or rights issue is identified, we correct the material and address affected distributions rather than simply remove the local copy.
Do
- Check rights before using standards, images or course materials.
- Attribute sources and respect licence conditions.
- Agree ownership and permitted reuse in client contracts.
- Obtain approval for statements on behalf of the company.
- Correct misleading public statements promptly.
Don’t
- Copy proprietary materials without permission.
- Publish confidential deliverables as marketing examples.
- Imply that management system certification endorses every service.
- Claim a client endorsement beyond the permission given.
- Present personal opinions as official company positions.
18Political activity, donations and public affairs
Our policy
Political engagement and charitable support must be transparent, properly authorised and never used to secure improper business advantage.
Community support and participation in public debate must remain separate from improper influence. A contribution can create risk even when the recipient is a legitimate organisation, particularly if a client or official requests it during a business decision. We examine the actual beneficiary, purpose and connection to pending matters before approval. Personal political choices remain personal and must not become a condition of employment or business access. Company representation in public affairs requires a clear mandate, accurate statements and records sufficient to explain what was supported and why.
Do
- Keep personal political activity separate from work.
- Check donation recipients and intended use.
- Seek approval for company-funded contributions or sponsorships.
- Record relevant contacts and expenditure accurately.
- Check applicable restrictions on lobbying and contributions.
Don’t
- Donate to influence a procurement or regulatory decision.
- Use company resources for personal campaigning without authority.
- Pressure colleagues to support a political cause.
- Hide the beneficiary of a sponsorship.
- Claim that personal political views represent Compliance House.
19Speaking up, investigations and records
Our policy
We encourage good-faith concerns, prohibit retaliation and protect fair, impartial fact-finding and relevant records.
Early reporting allows concerns to be assessed before harm grows. A reporter is not expected to prove a breach or conduct an investigation before seeking help. We distinguish an honest concern that cannot be substantiated from a deliberately false allegation. Reviews must be proportionate, impartial and respectful of privacy and procedural fairness. Relevant evidence must remain intact, including when normal deletion schedules would otherwise apply. Information is shared only as needed for legitimate handling and legal duties. Decisions and corrective actions should be documented, and lessons used to improve controls rather than focus solely on individual blame.
Do
- Raise concerns promptly with available facts.
- Preserve relevant records and follow retention instructions.
- Share case information only with authorised people.
- Cooperate honestly with authorised reviews.
- Disclose investigator conflicts and seek impartial handling.
Don’t
- Retaliate against a reporter, witness or person seeking advice.
- Knowingly make false allegations.
- Delete, alter or conceal evidence.
- Conduct unauthorised surveillance or access private accounts.
- Promise absolute secrecy or prejudge an allegation.
Advice and speaking up
Ethics Hotline
ethics@compliancehouse.net
Use this address to seek ethics guidance or report suspected misconduct. Describe the facts you know and any relevant dates. Before sharing sensitive documents, request a secure transfer method. If the concern involves those managing this mailbox, seek a conflict-free recipient or independent advice.
Information should be shared only on a need-to-know basis, subject to investigation needs and legal obligations. Good-faith reporting should be protected even if a concern is not substantiated. This Code does not restrict lawful external reporting rights. Contact local emergency services where there is immediate danger.
Implementation and accountability
Management should assign responsibility for implementation, training, controls and handling concerns. Breaches should be reviewed impartially, with corrective action and, where appropriate, proportionate disciplinary or contractual measures consistent with applicable law. The Code should be reviewed at least annually and after significant changes.
Approved by the Board - October 2026