New! AI Board Member: Walk into every meeting knowing nothing was missed. Request early accessarrow_forward
Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

What a defensible conflict of interest program actually looks like

August 10, 2026
4 min read
Lauren Bean

Lauren Bean

Staff Product Marketing Manager

Most COI programs look fine on paper. Here is what changes when a regulator, auditor or journalist asks you to prove it.

Every year, employees at most companies do the same thing: they open a form, tick a box confirming they have no conflicts of interest, and move on. The form gets filed. The exercise gets marked complete. And for years, that has been enough to call a conflict of interest program "in place."

It is not enough anymore.

The gap between having a COI process and having a COI program

Most compliance teams still run conflict of interest management on manual or partially manual workflows: spreadsheets, shared inboxes and legacy tools stitched together at review time. That is not a criticism of the compliance teams running them. It is a reflection of how COI has traditionally been treated, as a once-a-year certification exercise rather than an ongoing governance program.

The problem is that regulators have stopped grading on that curve. The SEC's own FY2026 examination priorities state that examiners now evaluate whether a firm's conflict of interest policies and procedures are not just documented but "implemented and enforced." That is a meaningful shift. It moves the test from "did you ask employees to disclose" to "can you show what happened after they did."

Recent PwC's research puts it plainly: conflicts of interest are too often treated as isolated ethical lapses when they are actually a systemic, company-wide risk hiding in plain sight. A disclosure that gets filed and forgotten is not a control. It is a paper trail with no follow-through, and follow-through is exactly what regulators, boards and fraud examiners say matters most. The Association of Certified Fraud Examiners estimates that organizations lose 5% of revenue to fraud every year, and undisclosed or unmanaged conflicts sit quietly underneath a large share of it.

Why "once a year" was never really the standard

Ask most compliance leaders what a strong COI program looks like and they will not describe a form. They will describe a lifecycle: a conflict gets disclosed, it gets reviewed against real risk criteria, it becomes a case with an owner, a mitigation plan gets put in place, and the outcome gets documented well enough that someone outside the compliance team could pick up the file and understand exactly what happened and why.

That is the definition of defensible. Not "we asked." Defensible means every disclosure can be traced through review, decision and mitigation, with a record that holds up when someone outside compliance goes looking for it: a regulator, an auditor, a new general counsel, a board committee.

Three things tend to separate programs that can produce that trail from programs that cannot:

Disclosures are treated as the start of a process, not the end of one. A "no conflicts to report" answer filed in January means nothing if a role change in June creates a new one that nobody re-evaluates. Circumstances shift. Programs that stay defensible are the ones built to catch that shift, not just the moment of initial disclosure.

Review capacity is spent on real risk, not volume. When every disclosure, low-risk or not, lands in the same queue, reviewers spend their time triaging noise instead of investigating the handful of cases that actually matter. The disclosures that should get the closest look are often the ones that get lost in the pile.

Reporting exists before someone asks for it. If producing a clear picture of open conflicts, trends and mitigation status for a board meeting or an audit takes a week of manual exports and cross-referencing, that is a sign the program was built to satisfy a checkbox, not to be examined. A defensible program can answer "show me" on short notice, because the record already exists in a usable form.

The pattern underneath this

None of this is unique to conflicts of interest. It is the same gap showing up across compliance more broadly: training that gets completed but not absorbed, policies that get published but not found, hotline reports that get logged but not connected to anything else happening in the business. COI is simply where it tends to surface first, because it is the program most CCOs assume is already solid.

The fix is not a bigger form or a stricter deadline. It is treating COI the way regulators already expect boards to treat governance generally, as a continuous, documented, closed-loop system, not a once-a-year exercise that gets reopened only when something goes wrong.

See how Diligent Conflict of Interest Manager turns disclosures into a defensible, closed-loop program →

Explore More

Implementing conflict of interest software

Blog

· Feb 2, 2026

· 12 min read

Conflict of interest software: A buyer's guide for compliance teams

Writing on governance, risk, compliance and audit since 2020

By Kezia Farnham

Evaluate conflict of interest software with this buyer's guide covering essential features, vendor questions and ROI framework.

Guide

· May 14, 2026

· 1 min read

From hotline to speak-up culture: Change management for modern whistleblowing

Explore how to transform outdated hotline systems into robust, AI-driven speak-up programs that meet modern regulatory demands. This guide provides compliance and legal leaders with a practical roadmap to enhance whistleblowing practices, ensuring early issue identification and reporter protection. Download now to begin your transition to a strategic speak-up culture.

Guide

· Feb 11, 2026

· 1 min read

7 pillars of effective policy management

Learn the 7 pillars of effective policy management. A modern framework for legal & compliance leaders to reduce risk & improve efficiency. Get the guide.