About

Conflict of Interest Controls for Stronger Governance

Conflict of Interest Controls for Stronger Governance
Published on 8/28/2026

Strong governance is tested in moments where personal interest, organisational duty and commercial opportunity meet. A director may have a family connection to a vendor. A manager may be asked to approve work performed by a former employer. A compliance officer may need to escalate a concern involving a senior executive. None of these situations automatically proves wrongdoing, but each one can damage confidence if the organisation has no clear way to identify and manage it.

For Jamaican organisations in 2026, conflict of interest controls should be treated as core governance infrastructure, not a formality completed once a year. They help boards, executives and compliance teams show that decisions are made fairly, risks are escalated early and sensitive matters are handled without improper influence.

The goal is not to pretend conflicts never happen. The goal is to make them visible, assess their seriousness, apply proportionate controls and keep evidence that the decision-making process was independent.

What is a conflict of interest in governance?

A conflict of interest arises when a person’s private interest could improperly influence, or appear to influence, the performance of their duties. The interest may be financial, personal, professional or reputational. It may involve the person directly or someone connected to them, such as a close relative, business partner, associate or organisation where they hold a role.

The OECD Recommendation on Public Integrity recognises conflict of interest management as part of a broader integrity system. That principle applies well beyond the public sector. Private companies, charities, financial institutions, professional firms and data-rich organisations all need practical controls that keep decision-making credible.

A useful governance programme distinguishes between three types of conflict:

Type of conflict

Meaning

Governance response

Actual conflict

A private interest is currently influencing, or can directly influence, an official duty

Immediate disclosure, assessment and mitigation before the decision proceeds

Potential conflict

A private interest could influence a future duty if circumstances change

Record the interest and monitor it before relevant decisions arise

Perceived conflict

A reasonable person could think the person’s judgement may be compromised, even if it is not

Manage transparently to protect trust in the decision-making process

Perceived conflicts deserve serious attention. Governance is not only about whether a decision was fair. It is also about whether the organisation can demonstrate fairness to regulators, shareholders, members, customers, employees and the wider public.

Why conflict of interest controls matter

Weak conflict controls create several governance risks at once. They can distort procurement, weaken oversight, compromise investigations, undermine compliance decisions and expose confidential information. They also make it harder for a board to defend its actions if a complaint, audit finding or regulatory review arises.

In smaller markets, including Jamaica, business and personal networks often overlap. Directors, executives and suppliers may know each other through professional associations, schools, community organisations or family connections. That reality is not a governance failure. The failure occurs when relationships are hidden, unmanaged or allowed to influence decisions without scrutiny.

Conflict of interest controls support stronger governance by helping organisations:

  • Identify interests before they affect important decisions

  • Protect the independence of board and management deliberations

  • Improve procurement and vendor selection integrity

  • Reduce fraud, bribery and corruption risk

  • Support anti-money laundering and compliance accountability

  • Protect sensitive information, including personal data in declarations

  • Create audit-ready evidence of fair decision-making

Conflict management also reinforces the accountability culture that boards need for wider governance obligations. Organisations that are already strengthening privacy, risk and compliance programmes can align conflict oversight with their broader approach to data privacy and governance accountability.

Where conflicts commonly arise

Conflicts are not limited to boardrooms. They appear across everyday operations, especially where people control money, information, appointments or approvals.

Common sources include procurement decisions, recruitment and promotion panels, related-party transactions, board appointments, external directorships, consulting arrangements, political or charitable affiliations, gifts and hospitality, confidential information access, regulatory engagement and internal investigations.

Some conflicts are obvious, such as a director voting on a contract involving a company they own. Others are more subtle. A manager may influence the evaluation of a vendor run by a former colleague. An employee may access customer records involving someone they know. A compliance reviewer may hesitate to escalate a breach because the responsible business unit leader controls their career progression.

A mature governance framework treats these scenarios as foreseeable risks. It does not depend on individual judgement alone.

The essential controls every organisation should have

Conflict of interest controls work best when they are simple enough to use and strong enough to withstand scrutiny. A policy that sits untouched in a shared folder will not change behaviour. The controls must be embedded into board processes, procurement, hiring, compliance reviews and management reporting.

Control

Purpose

Evidence to keep

Conflict of interest policy

Sets expectations, definitions, examples and consequences

Approved policy, review history and communication records

Disclosure declarations

Captures interests before or when they arise

Signed onboarding, annual and event-based declarations

Conflict register

Creates a central record of interests and decisions

Register entries, updates and access logs

Assessment process

Determines seriousness and required mitigation

Assessment notes, risk rating and approval trail

Recusal rules

Removes conflicted persons from influence

Meeting minutes, attendance records and voting records

Gifts and hospitality controls

Prevents improper influence through benefits

Gift register, approvals and declined offers

Related-party transaction review

Ensures independent scrutiny of connected transactions

Board papers, valuations and independent approvals

Training and certification

Builds awareness and personal accountability

Attendance records, assessment results and certifications

These controls should be scaled to the organisation. A small non-profit will not need the same machinery as a regulated financial institution, but both need clarity on disclosure, assessment, decision rights and evidence.

Start with a policy that people can actually apply

A strong conflict of interest policy should do more than define a conflict. It should tell people exactly when to disclose, whom to disclose to, what happens after disclosure and what consequences apply for non-disclosure.

The policy should include realistic examples tailored to the organisation’s activities. A procurement-heavy business should include supplier and tender scenarios. A financial institution should cover customer onboarding, beneficial ownership, suspicious transaction escalation and relationships with intermediaries. A data-driven organisation should address access to personal data, investigation files and confidential board information.

The policy should also clarify that disclosure is not an admission of misconduct. This matters because employees and directors may avoid reporting conflicts if they think disclosure will be treated as wrongdoing. The governance message should be clear: undisclosed conflicts are the problem. Timely disclosure is expected behaviour.

Define ownership and decision rights

Conflict controls fail when everyone assumes someone else is responsible. Boards should approve the framework and receive reporting on significant matters. Management should implement the policy and ensure that high-risk decisions include conflict checks. Compliance, legal, internal audit or the corporate secretary may maintain the register and coordinate reviews, depending on the organisation’s structure.

No person should be responsible for deciding the outcome of their own conflict. If a director, executive or committee member has an interest in a matter, the assessment should move to an independent reviewer, committee chair or board committee. For serious conflicts, the full board may need to be informed, excluding the conflicted individual from the relevant discussion.

Decision rights should be written down. The policy should state who can approve a mitigation plan, who can require recusal, who can permit continued participation with safeguards and who must receive escalation reports.

Build disclosure into the governance cycle

Annual declarations are useful, but they are not enough. Conflicts often arise between annual cycles, especially during tenders, transactions, hiring processes and investigations.

A practical disclosure model uses four triggers. First, onboarding declarations for directors, officers, employees, contractors and committee members in sensitive roles. Second, annual declarations to refresh the register. Third, event-based declarations when circumstances change. Fourth, transaction-specific confirmations before high-risk decisions, such as procurement awards, related-party transactions, investments, disciplinary matters or executive appointments.

This approach makes disclosure part of the organisation’s workflow rather than an isolated compliance exercise.

Maintain a conflict register with restricted access

A conflict register is the central record of disclosed interests, assessments, mitigation decisions and follow-up actions. It should be accurate, current and protected, because it may contain personal data, employment information, financial interests and family relationship details.

Register field

Why it matters

Name and role

Identifies the person and their decision-making authority

Nature of interest

Explains the relationship, financial interest or external role

Business area affected

Shows where the conflict may influence decisions

Conflict type

Records whether the matter is actual, potential or perceived

Risk rating

Helps prioritise attention and escalation

Mitigation decision

Documents recusal, restrictions, approval conditions or monitoring

Approver

Shows independent review and accountability

Review date

Ensures the conflict is revisited when circumstances change

Closure notes

Records why the conflict no longer applies, if relevant

Because the register may hold sensitive information, access should be limited to those who need it for governance, compliance or audit purposes. Organisations should also apply retention rules and confidentiality safeguards. Teams that handle declarations should follow the same discipline expected for confidentiality and data handling rules, particularly where personal data is involved.

A boardroom table holds conflict of interest declaration forms, a register binder, nameplates, pens, and a governance checklist for committee review.

Use mitigation controls that match the risk

Not every conflict requires the same response. A minor perceived conflict may be managed through disclosure and documentation. A serious actual conflict may require full recusal, removal from the decision process or termination of the conflicting arrangement.

Common mitigation options include excluding the conflicted person from receiving papers on the matter, requiring them to leave the meeting during discussion, preventing them from voting, appointing an independent evaluator, changing reporting lines, obtaining external advice, declining a gift or hospitality offer, divesting an interest or refusing the transaction entirely.

Recusal should be more than a sentence in the minutes. The organisation should be able to show that the conflicted person did not shape the decision indirectly. For example, if a director is conflicted in a vendor selection, they should not receive confidential evaluation materials, lobby other directors outside the meeting or influence the scope of the tender.

Apply stronger controls in high-risk areas

Conflict of interest controls should be stricter where the risk of financial loss, regulatory exposure or reputational harm is higher.

Procurement is one of the most important areas. Conflict checks should occur before tender evaluation begins, not after a preferred supplier emerges. Evaluation panel members should sign transaction-specific declarations, scoring should be documented and exceptions should be reviewed independently.

Anti-money laundering compliance also depends on independence. The FATF Recommendations emphasise risk-based policies, controls and procedures for managing money laundering and terrorist financing risks. Conflicts can weaken those controls if, for example, a relationship manager pressures compliance staff to approve a high-risk customer, a staff member has an undisclosed connection to an introducer or escalation decisions are influenced by revenue concerns.

Data protection and privacy matters can also involve conflicts. A person responsible for a failed process should not be the only reviewer of the resulting incident. A staff member with a personal relationship to a data subject should not access or handle that individual’s records unless there is a legitimate work need and appropriate oversight. Where conflict issues intersect with privacy governance, boards should ensure ownership, reporting and escalation are clear, consistent with wider privacy governance and board oversight.

Train people using realistic scenarios

Training should explain the policy, but it should also help people recognise conflicts in real situations. Many employees will not use legal or governance language to describe a conflict. They may say, “I know the supplier,” “my cousin works there,” “I used to consult for them” or “I do not want to get involved because my manager is connected to it.” Training should teach them that these are disclosure triggers.

Scenario-based sessions work particularly well for boards, procurement teams, compliance functions, HR, finance and senior management. Training should cover actual, potential and perceived conflicts, the difference between disclosure and approval, gifts and hospitality, confidential information, recusal, escalation and consequences for concealment.

Certification can also strengthen accountability. After training, directors and employees in sensitive roles can certify that they understand the policy, have disclosed relevant interests and will update the organisation if circumstances change.

Monitor compliance and report to the board

Conflict oversight should appear in regular governance reporting, not only when something goes wrong. Boards do not need personal details of every minor declaration, but they should receive enough information to understand trends, overdue actions and significant risks.

Useful board metrics include the percentage of annual declarations completed, number of new disclosures, number of high-risk conflicts, overdue mitigation actions, recusals recorded, gifts and hospitality exceptions, procurement conflicts, related-party matters and training completion rates.

The board should also review whether controls are working. If disclosures are unusually low, that may not mean the organisation has no conflicts. It may mean people do not understand the policy or do not trust the process. If recusals are not reflected in minutes, the evidence may be too weak to support the governance position later.

Many boards already review privacy, legal and compliance risks on a quarterly cycle. Conflict of interest reporting can be incorporated into the same governance rhythm used to monitor privacy legal risks boards should review, provided reporting remains focused and action-oriented.

Keep evidence that proves the control worked

In governance, evidence matters. A good decision with poor records can still look questionable during an audit, dispute or regulatory review. The organisation should retain signed declarations, register entries, assessment notes, approval records, meeting minutes, voting results, recusal confirmations, training records and policy communication evidence.

Meeting minutes should be specific enough to show what happened. If a director declared an interest and left the meeting, the minutes should record the declaration, departure, non-participation and return after the matter concluded. For procurement matters, the file should show when panel members declared interests and how any conflicts were managed before evaluation.

Internal audit or an independent reviewer should periodically test whether the policy is being followed. Sample testing can examine whether annual declarations were completed, high-risk decisions included conflict checks, recusals were documented and register entries were reviewed on time.

A practical 90-day implementation plan

Organisations that do not yet have mature conflict controls can make meaningful progress quickly. The first objective is to create a simple, defensible process, then improve it over time.

  1. Days 1 to 15, identify high-risk decision points: Map where conflicts could affect procurement, recruitment, board approvals, AML decisions, privacy incidents, investigations, grants, donations and related-party transactions.

  2. Days 16 to 30, approve or refresh the policy: Define conflicts, disclosure triggers, ownership, escalation paths, recusal rules, gifts and hospitality requirements and consequences for non-disclosure.

  3. Days 31 to 45, launch declarations: Collect onboarding, annual and role-based declarations from directors, executives, procurement staff, finance staff, compliance personnel and other sensitive roles.

  4. Days 46 to 60, build the register: Record disclosures, risk ratings, mitigation actions, approvers and review dates in a restricted-access register.

  5. Days 61 to 90, train and test: Deliver scenario-based training, test a sample of high-risk decisions and provide the board with a first conflict of interest report.

This timeline is realistic for many organisations, but complexity may increase where there are multiple subsidiaries, regulated activities, public-private partnerships or cross-border governance obligations.

Common mistakes to avoid

One common mistake is treating disclosure as the final step. Disclosure only starts the governance process. The organisation must still assess the interest, decide whether mitigation is required and document the outcome.

Another mistake is focusing only on financial conflicts. Personal relationships, career incentives, political connections, external roles and access to sensitive information can be just as important. A person may have no direct financial gain but still face pressure to act in a way that compromises independence.

Boards should also avoid informal workarounds. If a conflicted person quietly “steps back” but there is no minute, register entry or decision note, the organisation may struggle to prove the control was applied. Strong governance needs both good conduct and reliable records.

Frequently Asked Questions

What is the main purpose of conflict of interest controls? Conflict of interest controls help organisations identify, assess and manage situations where personal interests may affect official duties. They protect decision-making integrity and create evidence that governance processes are fair.

Does every disclosed conflict require recusal? No. Some conflicts can be managed through disclosure, monitoring or limited restrictions. Serious actual conflicts usually require stronger action, such as recusal from papers, discussions and voting.

Who should maintain the conflict of interest register? The register is often maintained by compliance, legal, the corporate secretary or another governance function. The key requirement is that access is restricted and conflicted persons do not decide the outcome of their own conflicts.

How often should conflict declarations be updated? Declarations should be collected at onboarding, refreshed annually and updated whenever circumstances change. High-risk transactions should also include transaction-specific conflict confirmations.

How do conflict controls support AML and data protection compliance? They help preserve independent decision-making in customer due diligence, escalation, investigations, incident reviews and access to sensitive information. This supports wider governance, risk and compliance accountability.

Strengthen governance before conflicts become disputes

Conflict of interest controls are most effective when they are designed before a sensitive decision, not after a challenge is raised. Clear policies, timely disclosure, independent assessment, documented recusal and board-level reporting give organisations the structure they need to make defensible decisions.

Privacy & Legal Management Consultants Ltd. supports organisations in Jamaica with governance, risk, compliance, data protection, AML compliance, cyber security and training. If your organisation needs help reviewing its conflict of interest framework or integrating it into a wider GRC programme, contact PLMC for a consultation.