
Every year, employees at most companies do the same thing: they open a form, tick a box confirming they have no conflicts of interest, and move on. The form gets filed. The exercise gets marked complete. And for years, that has been enough to call a conflict of interest program "in place."
It is not enough anymore.
Most compliance teams still run conflict of interest management on manual or partially manual workflows: spreadsheets, shared inboxes and legacy tools stitched together at review time. That is not a criticism of the compliance teams running them. It is a reflection of how COI has traditionally been treated, as a once-a-year certification exercise rather than an ongoing governance program.
The problem is that regulators have stopped grading on that curve. The SEC's own FY2026 examination priorities state that examiners now evaluate whether a firm's conflict of interest policies and procedures are not just documented but "implemented and enforced." That is a meaningful shift. It moves the test from "did you ask employees to disclose" to "can you show what happened after they did."
Recent PwC's research puts it plainly: conflicts of interest are too often treated as isolated ethical lapses when they are actually a systemic, company-wide risk hiding in plain sight. A disclosure that gets filed and forgotten is not a control. It is a paper trail with no follow-through, and follow-through is exactly what regulators, boards and fraud examiners say matters most. The Association of Certified Fraud Examiners estimates that organizations lose 5% of revenue to fraud every year, and undisclosed or unmanaged conflicts sit quietly underneath a large share of it.
Ask most compliance leaders what a strong COI program looks like and they will not describe a form. They will describe a lifecycle: a conflict gets disclosed, it gets reviewed against real risk criteria, it becomes a case with an owner, a mitigation plan gets put in place, and the outcome gets documented well enough that someone outside the compliance team could pick up the file and understand exactly what happened and why.
That is the definition of defensible. Not "we asked." Defensible means every disclosure can be traced through review, decision and mitigation, with a record that holds up when someone outside compliance goes looking for it: a regulator, an auditor, a new general counsel, a board committee.
Three things tend to separate programs that can produce that trail from programs that cannot:
Disclosures are treated as the start of a process, not the end of one. A "no conflicts to report" answer filed in January means nothing if a role change in June creates a new one that nobody re-evaluates. Circumstances shift. Programs that stay defensible are the ones built to catch that shift, not just the moment of initial disclosure.
Review capacity is spent on real risk, not volume. When every disclosure, low-risk or not, lands in the same queue, reviewers spend their time triaging noise instead of investigating the handful of cases that actually matter. The disclosures that should get the closest look are often the ones that get lost in the pile.
Reporting exists before someone asks for it. If producing a clear picture of open conflicts, trends and mitigation status for a board meeting or an audit takes a week of manual exports and cross-referencing, that is a sign the program was built to satisfy a checkbox, not to be examined. A defensible program can answer "show me" on short notice, because the record already exists in a usable form.
None of this is unique to conflicts of interest. It is the same gap showing up across compliance more broadly: training that gets completed but not absorbed, policies that get published but not found, hotline reports that get logged but not connected to anything else happening in the business. COI is simply where it tends to surface first, because it is the program most CCOs assume is already solid.
The fix is not a bigger form or a stricter deadline. It is treating COI the way regulators already expect boards to treat governance generally, as a continuous, documented, closed-loop system, not a once-a-year exercise that gets reopened only when something goes wrong.