Seed-stage B2B SaaS startup
Sample for a fictional organisation · 3,168 words[Company] Code of Conduct
- Version: 1.0
- Owner: CEO
- Approved by: Board
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
This code sets out the standards of behavior [Company] expects of everyone who works for it, and explains how to raise a concern. It applies to all employees, directors, contractors and anyone else working on [Company]'s behalf, and this code calls them "staff".
This code applies wherever staff are working or representing [Company]: when working remotely, in chat, email and video calls, at work events and when traveling for work, and in dealings with customers, suppliers and anyone else staff meet through their work. It applies to conduct outside work only where that conduct is directed at a colleague, a customer or a supplier, or uses the person's position at [Company].
Staff follow the law of each country where they work, and where that law requires more than this code or does not allow a rule in it, the law applies. Where [Company] sets a more detailed policy on a topic this code covers, that policy applies alongside this code, and the stricter rule applies. The rules for using [Company]'s systems, devices and accounts are set in [Company]'s acceptable use and information security policies, which this code does not repeat.
7. Gifts, Hospitality and Bribery
[Company] does not win or keep business, or obtain any advantage, by bribery, and no member of staff loses out for refusing to pay a bribe, even where [Company] loses business as a result.
- Staff must not offer, promise, give, ask for or accept a bribe, meaning anything of value intended to influence a decision improperly or to reward someone for acting improperly, and this rule applies to dealings with anyone, in government or in business, in any country, and whether the bribe is offered directly or through someone else.
- Staff must not make a facilitation payment, meaning a small unofficial payment to an official to speed up a routine action the official is already required to carry out.
- Staff must not give or accept cash, or anything that works like cash, such as a gift card, as a gift.
- Staff must not give a gift or hospitality to, or accept it from, a person who is deciding, or can influence, a tender or the award of a contract that is under way and that [Company] is bidding for or awarding, and this does not apply to a promotional item of low value that is offered to everyone.
- Staff may give or accept a gift or hospitality only where it is modest, occasional, openly given and has a clear business purpose.
- Staff must get the CEO's approval before giving or accepting a gift or hospitality worth more than $50 per person, and where a gift worth more than that figure arrives unasked, staff tell the CEO, who decides whether it is kept, shared or returned.
- Staff must not give anything of value, including a meal, to a public official or an employee of a government body without the CEO's approval in advance, whatever its value.
- Staff must not make a political donation in [Company]'s name or with its money, and must have the CEO's approval before making a charitable donation, or sponsoring a charity or community cause, in [Company]'s name.
- Staff who engage an agent, reseller or other third party to act for [Company] must tell it that this section applies to what it does for [Company].
- Staff who are asked for a bribe or a facilitation payment must refuse and tell the CEO at once.
- The CEO may approve a kind of hospitality or a named event in advance, as well as a single gift, and keeps a record of every approval given under this section; where the CEO's own gift, hospitality or donation needs an approval under this section, the board gives it.
9. Raising Concerns
[Company] wants to hear about a problem early, and anyone can raise a concern through the routes below without fear of being treated worse for it.
9.1 How to Raise a Concern
Staff are expected to raise:
- a suspected breach of the law;
- suspected bribery, fraud or false records;
- a danger to anyone's health or safety;
- retaliation against anyone who raised a concern;
- any other serious breach of this code; and
- an attempt to hide any of these.
A person who has been harassed, bullied or discriminated against is encouraged to raise it, and is never in breach of this code for choosing not to.
A concern can be raised through any of these routes:
- The CEO, at [Conduct contact email].
- A member of the board, at [Second contact name and email], where the concern is about the CEO or the person would rather not raise it with the CEO.
A concern can be raised in writing or in conversation, and without giving a name, and [Company] looks into an anonymous concern as far as the information given allows. A concern about the person a route leads to is raised through another route. Staff do not need proof, only an honest belief that something may be wrong. A security incident, a lost device or a suspected data breach is reported through [Company]'s incident reporting process, not through this section.
9.2 How Concerns Are Handled
- The CEO handles each concern, except that the board handles a concern that is about the CEO or that was raised with a member of the board.
- The CEO or the board, whichever is handling the concern, confirms to the person who raised it that it has been received, where that person gave a name, and decides how it is looked into and by whom.
- Whoever looks into a concern is impartial and has no part in what it is about.
- Staff must not investigate a concern themselves unless whoever is handling it asks them to.
- Whoever is handling a concern shares the identity of the person who raised it only with those who need it to look into the concern, or where the law requires it.
- Whoever is handling a concern tells the person it is about what has been said, and that person can respond before any decision is made.
- Staff who are asked for information must answer honestly.
- The CEO or the board, whichever is handling the concern, tells the person who raised it, where that person gave a name, when it is closed and, where it can be shared, the outcome, and keeps a record of the concern and its outcome.
9.3 Protection for People Who Speak Up
- [Company] does not allow retaliation, meaning treating someone worse, such as by dismissing, sidelining, threatening or harassing them, because they raised a concern in good faith or helped to look into one.
- Raising a concern in good faith means the person honestly believed what they said, and a concern raised in good faith is protected even where it turns out to be mistaken.
- Retaliation is itself a breach of this code and is handled under section 10.
- Staff who knowingly make a false report breach this code.
Nothing in this code, or in any confidentiality duty staff owe [Company], restricts staff from discussing their own pay, hours or working conditions with each other, from reporting a possible breach of the law to a regulator or law enforcement or taking legal advice about it without telling [Company] first, or from any other activity the law protects.
Under US law, an individual is not criminally or civilly liable under federal or state trade secret law for disclosing a trade secret in confidence to a government official or a lawyer solely to report or investigate a suspected breach of the law, or in a document filed under seal in a legal proceeding. An individual who files a lawsuit for retaliation by an employer for reporting a suspected breach of the law may disclose the trade secret to the individual's lawyer and use it in the court proceeding, provided the individual files any document containing the trade secret under seal and does not disclose the trade secret except under a court order.
Read the full example
[Company] Code of Conduct
- Version: 1.0
- Owner: CEO
- Approved by: Board
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
This code sets out the standards of behavior [Company] expects of everyone who works for it, and explains how to raise a concern. It applies to all employees, directors, contractors and anyone else working on [Company]'s behalf, and this code calls them "staff".
This code applies wherever staff are working or representing [Company]: when working remotely, in chat, email and video calls, at work events and when traveling for work, and in dealings with customers, suppliers and anyone else staff meet through their work. It applies to conduct outside work only where that conduct is directed at a colleague, a customer or a supplier, or uses the person's position at [Company].
Staff follow the law of each country where they work, and where that law requires more than this code or does not allow a rule in it, the law applies. Where [Company] sets a more detailed policy on a topic this code covers, that policy applies alongside this code, and the stricter rule applies. The rules for using [Company]'s systems, devices and accounts are set in [Company]'s acceptable use and information security policies, which this code does not repeat.
2. Principles
Every rule in this code applies one of five principles.
- Follow the law: Staff follow the law wherever they work and never break it for [Company]'s benefit.
- Act honestly: Staff tell the truth in records and in what they say to colleagues, customers and others, and put [Company]'s interests before personal gain when acting for it.
- Treat people with respect: Staff treat everyone they deal with at work with dignity.
- Protect what others entrust to [Company]: Staff look after the information, money and property that customers, colleagues and [Company] place in their care.
- Speak up: Staff raise a concern when something looks wrong, and nobody is treated worse for doing so.
Where this code gives no rule for a situation, staff ask whether the action is legal, whether it is honest, and whether they would be comfortable explaining it to a colleague, to a customer and to the board. Staff who are unsure ask the CEO before acting.
3. Roles and Responsibilities
- The CEO: keeps this code and advises staff on it; receives and decides the declarations made under section 6 and gives the approvals under section 7; receives concerns and handles them as section 9.2 says; keeps the records in section 11; arranges the training; and reports to the board as section 11 says.
- The board: approves this code and each change to it; holds everyone, including the most senior people, to the same standard; receives the report in section 11; receives and decides the CEO's own declarations under section 6 and those of directors who are not employees of [Company]; gives any approval the CEO needs under section 7; and handles any concern that is about the CEO or is raised with a member of the board.
- All staff: follow this code, complete the acknowledgment and training in section 11, declare conflicts as section 6 requires, get the approvals section 7 requires, and raise concerns as section 9 says.
4. Respect at Work
[Company] expects everyone to be treated with dignity at work, and does not tolerate harassment, bullying or discrimination by staff or against staff, whoever it comes from.
- Staff must not harass anyone, and harassment means unwanted conduct that is intended to violate a person's dignity or to create an intimidating, hostile, degrading, humiliating or offensive environment for them, or that has that effect, whether or not it was intended, where it is reasonable for the conduct to have that effect, such as unwelcome sexual advances, comments or contact, and slurs or jokes about a characteristic listed in the third bullet below.
- Staff must not bully anyone, and bullying means repeated or serious behavior that intimidates, humiliates or threatens a person, or a misuse of power over them, while giving fair feedback on someone's work and disagreeing about work are neither harassment nor bullying.
- Staff must not discriminate, and must make decisions about hiring, pay, promotion, work, discipline and dismissal on merit and never because of a person's age, disability, race, color, national or ethnic origin, religion or belief, sex, sexual orientation, gender identity, pregnancy or parental status, marital status, or any other characteristic protected by the law of the place where the person works. This rule does not prevent an adjustment or support for a person that the law requires or allows.
- Staff must not threaten anyone or use violence.
- These rules cover conduct toward colleagues, job applicants, customers, suppliers and anyone else staff meet through work, and conduct in chat, email, video calls and at work events as much as conduct in person.
- [Company] takes steps to prevent harassment of its staff, including sexual harassment and harassment by customers, suppliers and other people outside [Company], and acts when it is told of it.
- A person who is harassed, bullied or discriminated against does not have to confront the person responsible before raising it, and can raise it through any route in section 9.1.
5. Honesty and Fair Dealing
- Staff must keep records that are accurate and complete, including financial records, expense claims, time records, sales figures and the records that show [Company]'s security and compliance controls are working, and must not falsify, backdate or alter a record to mislead anyone.
- Staff must claim expenses only for real costs of [Company]'s work.
- Staff must make sure that what they tell customers, and anyone else outside [Company], about [Company], its products and services is true and not misleading, which includes answers to customers' security questionnaires, audits and due diligence requests, and staff must never claim a control, certification or capability [Company] does not have.
- Staff must not steal, commit fraud, or misuse money or property that belongs to [Company], its customers or its suppliers.
- Staff must commit [Company] to a contract, a payment or a public statement only within the authority their role gives them.
- Staff must choose suppliers on price, quality and suitability, and never because of a personal relationship or benefit.
- Staff must not agree with a competitor on prices, bids, or which customers or markets each will serve, and must not obtain a competitor's confidential information by improper means, including from a new colleague's former employer.
- Staff must cooperate honestly with audits, reviews and investigations, and must not destroy, alter or hide a record to defeat one.
6. Conflicts of Interest
A conflict of interest is any personal interest, relationship or outside activity that could affect, or could reasonably be seen to affect, a decision a person makes for [Company]. Having a conflict is not a breach of this code, but hiding one is.
The most common conflicts are these:
- outside work, including self-employment and advisory or board roles, that competes with [Company], is for one of its customers or suppliers, or would use its time, resources or confidential information;
- a financial interest in a customer, supplier or competitor, other than a small holding of publicly traded shares;
- a relative, partner or close friend who works for, or has an interest in, a customer, supplier or competitor;
- a relative or partner inside [Company] whom the person would hire, supervise or set pay for; and
- a business opportunity the person learns of through their work.
The rules for conflicts are these:
- Staff must declare a conflict in writing to the CEO, at [Conduct contact email], as soon as they become aware of it and before taking part in any decision it could affect.
- Staff who have declared a conflict take no part in the decision until the CEO, or the board for a declaration made to the board, has decided how it is handled, and then follow the conditions set.
- The CEO decides each declaration made to the CEO, and keeps a record of the declaration and the decision.
- The CEO, and each director who is not an employee of [Company], declare their own conflicts to the board, and the board decides them and gives any approval the next bullet requires for their outside work.
- Staff must have the CEO's approval before taking on outside work that competes with [Company], is for one of its customers or suppliers, or would use its time, resources or confidential information; other outside work needs no approval and need not be declared.
- Each time staff acknowledge this code under section 11, they confirm that they have declared every conflict they have.
7. Gifts, Hospitality and Bribery
[Company] does not win or keep business, or obtain any advantage, by bribery, and no member of staff loses out for refusing to pay a bribe, even where [Company] loses business as a result.
- Staff must not offer, promise, give, ask for or accept a bribe, meaning anything of value intended to influence a decision improperly or to reward someone for acting improperly, and this rule applies to dealings with anyone, in government or in business, in any country, and whether the bribe is offered directly or through someone else.
- Staff must not make a facilitation payment, meaning a small unofficial payment to an official to speed up a routine action the official is already required to carry out.
- Staff must not give or accept cash, or anything that works like cash, such as a gift card, as a gift.
- Staff must not give a gift or hospitality to, or accept it from, a person who is deciding, or can influence, a tender or the award of a contract that is under way and that [Company] is bidding for or awarding, and this does not apply to a promotional item of low value that is offered to everyone.
- Staff may give or accept a gift or hospitality only where it is modest, occasional, openly given and has a clear business purpose.
- Staff must get the CEO's approval before giving or accepting a gift or hospitality worth more than $50 per person, and where a gift worth more than that figure arrives unasked, staff tell the CEO, who decides whether it is kept, shared or returned.
- Staff must not give anything of value, including a meal, to a public official or an employee of a government body without the CEO's approval in advance, whatever its value.
- Staff must not make a political donation in [Company]'s name or with its money, and must have the CEO's approval before making a charitable donation, or sponsoring a charity or community cause, in [Company]'s name.
- Staff who engage an agent, reseller or other third party to act for [Company] must tell it that this section applies to what it does for [Company].
- Staff who are asked for a bribe or a facilitation payment must refuse and tell the CEO at once.
- The CEO may approve a kind of hospitality or a named event in advance, as well as a single gift, and keeps a record of every approval given under this section; where the CEO's own gift, hospitality or donation needs an approval under this section, the board gives it.
8. Confidentiality and Use of Resources
Confidential information at [Company] includes the personal information and other data that customers entrust to it, together with customer contracts, security and compliance details, source code, product plans and financial information. Staff use confidential information only for their work, share it only with people who need it for theirs, never use it for personal gain or to benefit anyone else, do not look at customer or colleague records out of curiosity, bring no confidential information from a former employer into [Company], and remain bound by these duties after they leave. Section 9.3 says what these duties never restrict.
[Company]'s money, equipment, systems, name and brand are for [Company]'s work, and staff use them with care and never for personal gain. Staff speak for [Company] in public only where their role authorizes it, and the detailed rules for systems, devices and accounts are in [Company]'s acceptable use and information security policies.
9. Raising Concerns
[Company] wants to hear about a problem early, and anyone can raise a concern through the routes below without fear of being treated worse for it.
9.1 How to Raise a Concern
Staff are expected to raise:
- a suspected breach of the law;
- suspected bribery, fraud or false records;
- a danger to anyone's health or safety;
- retaliation against anyone who raised a concern;
- any other serious breach of this code; and
- an attempt to hide any of these.
A person who has been harassed, bullied or discriminated against is encouraged to raise it, and is never in breach of this code for choosing not to.
A concern can be raised through any of these routes:
- The CEO, at [Conduct contact email].
- A member of the board, at [Second contact name and email], where the concern is about the CEO or the person would rather not raise it with the CEO.
A concern can be raised in writing or in conversation, and without giving a name, and [Company] looks into an anonymous concern as far as the information given allows. A concern about the person a route leads to is raised through another route. Staff do not need proof, only an honest belief that something may be wrong. A security incident, a lost device or a suspected data breach is reported through [Company]'s incident reporting process, not through this section.
9.2 How Concerns Are Handled
- The CEO handles each concern, except that the board handles a concern that is about the CEO or that was raised with a member of the board.
- The CEO or the board, whichever is handling the concern, confirms to the person who raised it that it has been received, where that person gave a name, and decides how it is looked into and by whom.
- Whoever looks into a concern is impartial and has no part in what it is about.
- Staff must not investigate a concern themselves unless whoever is handling it asks them to.
- Whoever is handling a concern shares the identity of the person who raised it only with those who need it to look into the concern, or where the law requires it.
- Whoever is handling a concern tells the person it is about what has been said, and that person can respond before any decision is made.
- Staff who are asked for information must answer honestly.
- The CEO or the board, whichever is handling the concern, tells the person who raised it, where that person gave a name, when it is closed and, where it can be shared, the outcome, and keeps a record of the concern and its outcome.
9.3 Protection for People Who Speak Up
- [Company] does not allow retaliation, meaning treating someone worse, such as by dismissing, sidelining, threatening or harassing them, because they raised a concern in good faith or helped to look into one.
- Raising a concern in good faith means the person honestly believed what they said, and a concern raised in good faith is protected even where it turns out to be mistaken.
- Retaliation is itself a breach of this code and is handled under section 10.
- Staff who knowingly make a false report breach this code.
Nothing in this code, or in any confidentiality duty staff owe [Company], restricts staff from discussing their own pay, hours or working conditions with each other, from reporting a possible breach of the law to a regulator or law enforcement or taking legal advice about it without telling [Company] first, or from any other activity the law protects.
Under US law, an individual is not criminally or civilly liable under federal or state trade secret law for disclosing a trade secret in confidence to a government official or a lawyer solely to report or investigate a suspected breach of the law, or in a document filed under seal in a legal proceeding. An individual who files a lawsuit for retaliation by an employer for reporting a suspected breach of the law may disclose the trade secret to the individual's lawyer and use it in the court proceeding, provided the individual files any document containing the trade secret under seal and does not disclose the trade secret except under a court order.
10. Breaches of This Code
This code applies to everyone equally, whatever their seniority. A breach may lead to action ranging from a reminder or retraining, through restricting or removing access, to disciplinary action up to dismissal, in line with [Company]'s disciplinary process and the employment law of the country where the person works. For contractors and other non-employees, a breach may lead to the engagement ending, and illegal activity may be reported to law enforcement. The response is proportionate to the breach and applied consistently, and takes into account how serious the breach was, whether it was deliberate, whether it has happened before, and whether the person raised it themselves and cooperated.
11. Acknowledgment, Training and Review
Every person in scope reads and acknowledges this code when they join, no later than their first day, and again after any material change and at least every 12 months, which may be done together with the acknowledgment of other policies. The CEO makes sure new staff are taken through this code when they join and that all staff receive a refresher at least every 12 months.
The CEO keeps these records: each acknowledgment, with the person's name, the date and the version of this code; the declarations and decisions made under section 6; the approvals given under section 7; and each concern the CEO handles under section 9.2 and its outcome.
At least every 12 months the CEO reports to the board the number of concerns the CEO handled and how each was resolved, without identifying anyone who raised one, the declarations and approvals recorded, and how many staff have acknowledged this code. The CEO reviews this code at least every 12 months and after any significant change in the law or in how [Company] works, with each change approved by the board.
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. It is provided "as is", without warranty of any kind, express or implied, and no liability is accepted for any loss or damage arising from its use. It is used at your own discretion. Review it with a qualified adviser before adopting it.