Disclosure Process
How disclosures are collected, managed, and reviewed.
Conflicts of Interest
Take the self-assessment. Learn where your program sits and steps you can take to improve.
5 Dimensions of Maturity
How disclosures are collected, managed, and reviewed.
How COI data connects across risk and compliance systems.
How data identifies risk, informs decisions, and measures effectiveness.
How policies and workflows support compliance.
How employees engage with and support the program.
Take the Assessment
If the embedded assessment does not load in your browser, open it in a new tab.
The Maturity Model
Manual processes with little visibility.
Siloed workflows with limited insight.
Standardized workflows and centralized data.
Integrated systems with real-time insights.
Predictive intelligence aligned across the enterprise.
By submitting this form you agree to receive communications from GAN Integrity. We'll never share your information with third parties.
Proven Results
Research commissioned by Apax in 2023, comparing GAN Integrity users against competing solutions.
significantly reduced risk exposure vs. 50% for competitors
increased employee satisfaction vs 40% for competitors
observed increase in ethical behavior vs. 39% for competitors
Resource
Detailed phase breakdowns, a comparison matrix, and real customer outcomes, free to download.
Customer Results
completion achieved in a single year, moving from manual processes to a centralized platform with automated workflows and enterprise HR integration.
Disclosure review time cut by two-thirds after replacing a home-built system with automated triage and real-time dashboards.
Of prior-year disclosures completed on the first day of launch, proof that a frictionless experience drives participation.
Frequently Asked Questions
A conflict of interest exists when an employee's personal interests could interfere with their ability to act in the best interests of the organization. This includes financial interests in vendors or competitors, personal relationships that influence hiring or contracting decisions, outside employment, board memberships, and gifts or hospitality received from business partners. The compliance obligation is not just to prohibit conflicts but to surface them, evaluate them, and document what was decided. An undisclosed conflict that later emerges is far more damaging than one that was disclosed and managed.
A mature COI program collects disclosures systematically across the employee population, routes them to the right reviewers automatically, connects disclosure data to third-party risk and gifts records, and produces evidence that the program is working. Participation rates above 90% are achievable with the right platform and frictionless disclosure process. Mature programs do not just collect annual declarations. They capture disclosures on an ongoing basis, flag new conflicts when they arise, and maintain a searchable record that holds up under audit.
Anything below 80% indicates a process problem, not an employee problem. Organizations that run paper-based or email-driven disclosure processes routinely see completion rates in the 40% to 60% range because the friction of the process works against participation. Organizations that deploy a purpose-built platform with single sign-on, pre-populated prior-year data and automated reminders regularly achieve 90% or above. One GAN Integrity customer moved from 40% to over 90% completion in a single year. The tool is not the whole answer, but it removes the barriers that hold programs back.
At minimum annually, but best practice is continuous disclosure. Annual campaigns capture what employees know at the time of the campaign. They miss new conflicts that arise throughout the year: a new investment, a family member joining a vendor, a side business that intersects with company relationships. A mature program requires employees to update their disclosures within 30 days of a material change, not just at the annual window. The system should make that easy. If updating a disclosure requires navigating a paper form or an email chain, employees will not do it promptly.
The disclosure should be reviewed by the right person within a defined timeframe, a decision should be documented, and the employee should receive a response. That sounds simple. In practice most programs fail at all three. Reviews pile up in compliance inboxes, decisions are made verbally and not recorded, and employees hear nothing for weeks. A mature program routes disclosures automatically based on the type and severity of the conflict, tracks review time, and closes every disclosure with a documented outcome. That audit trail is what you show regulators.
A vendor that an employee has a financial interest in should appear as a risk signal in your TPRM program. An employee who regularly receives gifts from a specific supplier should be visible alongside that supplier's risk profile. When COI and TPRM run in separate systems these connections are invisible. A compliance officer has to manually cross-reference two databases to spot the pattern. A connected platform surfaces the relationship automatically: the vendor file shows associated employee disclosures, and the disclosure record shows the vendor's screening status. That is the difference between a program that finds problems and one that misses them.
The DOJ ECCP evaluates whether a company has effective mechanisms to identify and manage conflicts of interest. Prosecutors look for a clear policy that defines conflicts and disclosure obligations, a process that makes disclosure easy for employees, evidence that disclosures are reviewed and acted on, and documentation showing the program caught and addressed potential conflicts. A program that collects disclosures and files them without review does not satisfy the ECCP standard. The question is not whether you have a policy. It is whether the policy works in practice.
A conflict of interest is a situation that creates potential for bias or improper influence. It is not necessarily a violation. An employee who discloses a financial interest in a vendor has done the right thing. The conflict becomes a violation if the employee fails to disclose it, or if they take action to benefit the vendor despite a conflict that should have been recused. Code of conduct violations are the outcome of conflicts that were not managed. A mature COI program is designed to prevent violations by surfacing conflicts before they become problems, not after.
Five metrics matter: completion rate (what percentage of the employee population submitted disclosures), review rate (what percentage of submitted disclosures were reviewed within the target timeframe), resolution rate (what percentage were closed with a documented outcome), recurrence rate (how many employees had disclosures flagged in prior years that should have triggered follow-up), and escalation rate (what percentage required senior review or action). Programs that can report on all five have the evidence base to demonstrate effectiveness. Programs that only track whether the campaign went out do not.
Three reasons: they do not know they have a conflict, the disclosure process is too difficult, or they are worried about the consequences of disclosing. The first is a training problem. The second is a process and technology problem. The third is a culture problem. Most programs overinvest in policy and underinvest in making disclosure frictionless and psychologically safe. Employees are more likely to disclose when the process takes two minutes, when they understand the purpose, and when they see that disclosures are handled professionally rather than used against them.
Gifts and entertainment disclosures capture what employees receive from or give to business partners. COI disclosures capture personal interests that could influence business decisions. The two are related but distinct. An employee who receives a gift above the policy threshold submits a G&E disclosure. An employee who has a financial interest in a vendor submits a COI disclosure. A mature compliance program captures both and connects them: if the same vendor appears in both a gift disclosure and a COI disclosure from the same employee, that pattern is a risk signal. Siloed programs miss it.
Yes, and this is underappreciated. A well-designed COI program is often the first touchpoint employees have with compliance software. If the experience is frictionless and the communication around it is clear, it builds confidence that the compliance program is there to help, not to catch people out. Organizations that see high COI completion rates typically also see higher engagement with training, hotline usage, and policy acknowledgment. The COI disclosure is a moment of contact between the compliance function and every employee in the organization. A good experience makes the next interaction easier.
Let's Get Started
Download the guide to see where you stand, or talk to our team about building a more mature COI program with GAN Integrity.