General Information

Abstract

This document provides guidance to organizations on how to identify, assess, resolve and monitor conflict of interest based on the principles of trust, integrity, transparency and accountability. The guidance in this document is generic and intended to be applicable to all organizations, regardless of type, size and nature of activity and whether in the public, private or not-for-profit sectors. It distinguishes between actual, apparent and potential conflict of interest.

Status
Published
Publication Date
10-Sep-2025
Current Stage
6060 - International Standard published
Start Date
11-Sep-2025
Due Date
08-Nov-2025
Completion Date
11-Sep-2025

Buy Documents

Standard

ISO 37009:2025 - Conflict of interest in organizations — Guidance Released:11. 09. 2025

English language (20 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

ISO 37009:2025 - Conflict of interest in organizations — Guidance

Release Date:16-Jul-2026
Spanish language (21 pages)
sale 15% off
Preview
sale 15% off
Preview

Overview

ISO 37009:2025 - Conflict of interest in organizations - Guidance provides practical, sector‑neutral guidance for identifying, assessing, resolving and monitoring conflicts of interest. Built on the principles of trust, integrity, transparency and accountability, the standard is intended for all organization types (public, private and not‑for‑profit) and distinguishes between actual, apparent and potential conflict of interest. ISO 37009 is a guidance document (no normative references) that complements governance, compliance and risk management frameworks.

Key topics

ISO 37009 organizes conflict‑of‑interest management into a structured framework and covers these technical topics:

  • Principles and framework: core values (trust, integrity, transparency, accountability) that underpin policies and processes.
  • Leadership and policy: leadership commitment, governance responsibilities, and policy development for conflict‑of‑interest management.
  • Roles and responsibilities: duties of the governing body, top management and personnel in prevention and remediation.
  • Support mechanisms: required resources, competence, awareness, training and communication to implement the framework.
  • Process lifecycle:
    • Identification (including disclosure procedures)
    • Assessment of actual, apparent and potential conflicts
    • Resolution procedures and decision‑making safeguards
    • Monitoring strategies to track and control conflict‑of‑interest risks
  • Performance evaluation: review, compliance checks and evaluation of framework effectiveness.
  • Annex and guidance: Annex A provides practical material on managing conflict of interest.

Practical applications

ISO 37009 helps organizations embed conflict‑of‑interest management into their governance and operational processes to:

  • Mitigate risk and reduce corruption exposure
  • Strengthen ethical decision‑making and stewardship
  • Protect reputation and build stakeholder trust
  • Improve compliance and dovetail with enterprise risk management

Typical users and functions:

  • Boards and governing bodies setting policy and oversight
  • Top management implementing governance and controls
  • Compliance, legal, HR and procurement teams operating disclosure, assessment and resolution processes
  • Internal audit and risk teams monitoring effectiveness and reporting

Related standards

ISO 37009 is intended to be used alongside other governance and integrity standards, including:

  • ISO 37000 (governance of organizations)
  • ISO 37001, ISO 37002, ISO 37003, ISO 37004, ISO/TS 37008 (anti‑bribery, whistleblowing and integrity tools)
  • ISO 37301 (compliance management)
  • ISO 31000 (risk management)

Keywords: ISO 37009, conflict of interest, conflict-of-interest management, governance, trust, integrity, transparency, accountability, risk management.

Buy Documents

Standard

ISO 37009:2025 - Conflict of interest in organizations — Guidance Released:11. 09. 2025

English language (20 pages)
sale 15% off
Preview
sale 15% off
Preview
Standard

ISO 37009:2025 - Conflict of interest in organizations — Guidance

Release Date:16-Jul-2026
Spanish language (21 pages)
sale 15% off
Preview
sale 15% off
Preview

Get Certified

Connect with accredited certification bodies for this standard

Great Wall Tianjin Quality Assurance Center

Established 1993, first batch to receive national accreditation with IAF recognition.

CNAS China Verified

Hong Kong Quality Assurance Agency (HKQAA)

Hong Kong's leading certification body.

HKAS Hong Kong Verified

Innovative Quality Certifications Pvt. Ltd. (IQCPL)

Known for integrity, providing ethical & impartial Assessment & Certification. CMMI Institute Partner.

NABCB India Verified

Sponsored listings

Frequently Asked Questions

ISO 37009:2025 is a standard published by the International Organization for Standardization (ISO). Its full title is "Conflict of interest in organizations — Guidance". This standard covers: This document provides guidance to organizations on how to identify, assess, resolve and monitor conflict of interest based on the principles of trust, integrity, transparency and accountability. The guidance in this document is generic and intended to be applicable to all organizations, regardless of type, size and nature of activity and whether in the public, private or not-for-profit sectors. It distinguishes between actual, apparent and potential conflict of interest.

This document provides guidance to organizations on how to identify, assess, resolve and monitor conflict of interest based on the principles of trust, integrity, transparency and accountability. The guidance in this document is generic and intended to be applicable to all organizations, regardless of type, size and nature of activity and whether in the public, private or not-for-profit sectors. It distinguishes between actual, apparent and potential conflict of interest.

ISO 37009:2025 is classified under the following ICS (International Classification for Standards) categories: 03.080.99 - Other services. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO 37009:2025 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


SLOVENSKI STANDARD
01-november-2025
Konflikt interesov v organizacijah - Napotki
Conflict of interest in organizations - Guidance
Conflits d'intérêts dans les organisations — Recommandations
Ta slovenski standard je istoveten z: ISO 37009:2025
ICS:
03.100.01 Organizacija in vodenje Company organization and
podjetja na splošno management in general
03.100.02 Upravljanje in etika Governance and ethics
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

International
Standard
ISO 37009
First edition
Conflict of interest in
2025-09
organizations — Guidance
Conflits d'intérêts dans les organisations — Recommandations
Reference number
© ISO 2025
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
Contents Page
Foreword .v
Introduction .vi
1 Scope .1
2 Normative references .1
3 Terms and definitions .1
4 Understanding conflict of interest .4
4.1 General .4
4.2 Nature of interest .5
4.2.1 General .5
4.2.2 Personal interest .5
4.2.3 Organizational interest .5
4.3 Category of conflict of interest .5
4.3.1 General .5
4.3.2 Actual conflict of interest .6
4.3.3 Apparent conflict of interest .6
4.3.4 Potential conflict of interest .6
5 Framework .6
5.1 General .6
5.2 Principles .7
5.2.1 General .7
5.2.2 Trust .7
5.2.3 Integrity .8
5.2.4 Transparency . . .8
5.2.5 Accountability .8
6 Leadership . 9
6.1 Leadership and commitment .9
6.2 Policy .9
6.3 Roles and responsibilities .9
6.3.1 Governing body .9
6.3.2 Top management .9
7 Support .10
7.1 Resources .10
7.2 Competence .10
7.3 Awareness and training .10
7.4 Communication .11
8 Process . .11
8.1 General .11
8.2 Identification . 12
8.2.1 General . 12
8.2.2 Identification process . 12
8.2.3 Disclosure . 13
8.3 Assessment . 13
8.3.1 General . 13
8.3.2 Assessment process . 13
8.4 Resolution .14
8.4.1 General .14
8.4.2 Resolution process .14
8.5 Monitoring .14
8.5.1 General .14
8.5.2 Monitoring strategies .14
9 Performance evaluation .15

iii
9.1 Review, assessment and compliance. 15
9.2 Evaluating framework effectiveness . 15
Annex A (informative) Managing conflict of interest .16
Bibliography .20

iv
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO document should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 309, Governance of organizations.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.

v
Introduction
This document provides guidance on understanding conflict of interest and how to identify and manage
it for organizations of all types. Conflict of interest (whether actual, potential or perceived) can obstruct
the objectivity and fairness of any decision-making process. Unmanaged conflict of interest is one of the
key risks contributing to corruption or other types of wrongdoings or contributing to the perception of
wrongdoing or other serious risks.
Though conflict of interest is not necessarily corruption, conflict of interest can adversely impact effective
performance, responsible stewardship and ethical behaviour in an organization or the public.
Therefore, organizations should have an effective conflict of interest management framework in place to
ensure that interested parties declare their conflict of interest in time and it is properly managed. Conflict
of interest is a risk by nature and its management will benefit from a governance, risk management and
compliance framework.
This document provides guidance to organizations on understanding conflict of interest and how to
manage conflict of interest based on the principles of trust, integrity, transparency and accountability. It
distinguishes and provides guidance on dealing with actual, apparent and potential conflict of interest.
Potential benefits to the organization include but are not limited to:
a) mitigating risks related to conflict of interest;
b) promoting good governance outcomes, such as effective performance, responsible stewardship and
ethical behaviour;
c) protecting the reputation and building trust;
d) strengthening the decision-making processes;
e) improving and fostering overall compliance performance.
The conflict-of-interest management framework should be an integral part of management, embedded in
the culture and practices, and tailored to the business processes of the organization. The framework for
managing conflict of interest is outlined in this document.
This document should be read in conjunction with other relevant standards and publications that cover
integrity-related risks including:
— ISO 37000
— ISO 37001
— ISO 37002
— ISO 37003
— ISO 37301
— ISO 37004
— ISO/TS 37008
— ISO 31000
NOTE 1 Guidance for governance of organizations is provided in ISO 37000.
NOTE 2 Requirements for a general compliance management system are specified in ISO 37301.

vi
International Standard ISO 37009:2025(en)
Conflict of interest in organizations — Guidance
1 Scope
This document provides guidance to organizations on how to identify, assess, resolve and monitor conflict of
interest based on the principles of trust, integrity, transparency and accountability.
The guidance in this document is generic and intended to be applicable to all organizations, regardless of
type, size and nature of activity and whether in the public, private or not-for-profit sectors. It distinguishes
between actual, apparent and potential conflict of interest.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
organization
person or group of people that has its own functions with responsibilities, authorities and relationships to
achieve its objectives
Note 1 to entry: The concept of organization includes, but is not limited to, sole-trader, company, corporation, firm,
enterprise, authority, partnership, charity or institution, or part or combination thereof, whether incorporated or not,
public or private.
[SOURCE: ISO 37301:2021, 3.1, modified — Note 2 to entry has been deleted.]
3.2
interested party (preferred term)
stakeholder (admitted term)
person or organization (3.1) that can affect, be affected by or perceive itself to be affected by a decision or
activity.
Note 1 to entry: An interested party can be internal or external to the organization.
[SOURCE: ISO 37001:2025, 3.3]
3.3
personnel
organization's (3.1) directors, officers, employees, temporary staff or workers, and volunteers
[SOURCE: ISO 37001:2025, 3.24, modified — Note 1 to entry and Note 2 to entry have been deleted.]

3.4
governing body
person or group of persons who have ultimate accountability for the whole organization (3.1)
Note 1 to entry: A governing body can be explicitly established in a number of formats including, but not limited to, a
board of directors, supervisory board, sole director, joint and several directors, or trustees.
Note 2 to entry: ISO management system standards make reference to the term “top management” to describe a role
that, depending on the standard and organizational context, reports to, and is held accountable by, the governing body.
Note 3 to entry: Not all organizations, particularly small and medium organizations, have a governing body separate
from top management. In such cases, top management exercises the role of the governing body.
[SOURCE: ISO 37000:2021, 3.3.4, modified — Note 1 to entry has been deleted; Note 3 to entry has been added.]
3.5
governance policy
intentions and direction of an organization (3.1), as formally expressed by its governing body (3.4)
[SOURCE: ISO 37000:2021, 3.2.9]
3.6
top management
person or group of people who directs and controls an organization (3.1) at the highest level
Note 1 to entry: Top management has the power to delegate authority and provide resources within the organization.
[SOURCE: ISO 37301:2021, 3.3, modified — Note 2 to entry and Note 3 to entry have been deleted.]
3.7
risk
effect of uncertainty on objectives
Note 1 to entry: An effect is a deviation from the expected - positive or negative.
Note 2 to entry: Uncertainty is the state, even partial, of deficiency of information related to, understanding or
knowledge of, an event, its consequence, or likelihood.
Note 3 to entry: Risk is often characterized by reference to potential events and consequences, or a combination of these.
Note 4 to entry: Risk is often expressed in terms of a combination of the consequences of an event (including changes
in circumstances) and the associated likelihood of occurrence.
[SOURCE: ISO 37301:2021, 3.7]
3.8
process
set of interrelated or interacting activities that use or transform inputs to deliver a result
Note 1 to entry: Whether the result of a process is called an output, a product or a service depends on the context of
the reference.
[SOURCE: ISO 37301:2021, 3.8]
3.9
documented information
information required to be controlled and maintained by an organization (3.1) and the medium on which it
is contained
Note 1 to entry: Documented information can be in any format and media and from any source.
[SOURCE: ISO 37301:2021, 3.10, modified — Note 2 to entry deleted]

3.10
effectiveness
extent to which planned activities are realized and planned results achieved
[SOURCE: ISO 37301:2021, 3.13]
3.11
performance
measurable result
Note 1 to entry: Performance can relate either to quantitative or qualitative findings.
Note 2 to entry: Performance can relate to managing activities, processes (3.8), products, services, systems or
organizations (3.1).
[SOURCE: ISO 37301:2021, 3.11]
3.12
continual improvement
recurring activity to enhance performance (3.11)
[SOURCE: ISO 37301:2021, 3.12]
3.13
conflict of interest
situation in which an interested party has personal interest or organizational interest, directly or indirectly,
that can compromise or interfere with the ability to act impartially in carrying out their duties in the best
interest of the organization
Note 1 to entry: There can be different types of personal interests: business, financial, family, professional, religious
or political.
Note 2 to entry: Organizational interest relates to the interests of an organization or part of an organization (e.g. team
or department) rather than an individual.
3.14
measurement
process (3.8) to determine a value
[SOURCE: ISO 37301:2021, 3.19]
3.15
monitoring
determining the status of a system, a process (3.8) or an activity
Note 1 to entry: To determine the status, there can be a need to check, supervise or critically observe.
[SOURCE: ISO 37301:2021, 3.20]
3.16
business associate
external party with whom the organization (3.1) has, or plans to establish, some form of business relationship
Note 1 to entry: Business associate includes but is not limited to clients, customers, joint ventures, joint venture
partners, consortium partners, outsourcing providers, contractors, consultants, sub-contractors, suppliers, vendors,
advisors, agents, distributors, representatives, intermediaries and investors. This definition is deliberately broad.
Note 2 to entry: Different types of business associate pose different types and degrees of conflict of interest (3.13)risk
(3.7), and an organization will have differing degrees of ability to influence different types of business associate.
Note 3 to entry: Reference to "business" in this document can be interpreted broadly to mean those activities that are
relevant to the purposes of the organization's existence.

[SOURCE: ISO 37001:2025, 3.25, modified — The last sentence in Note 1 to entry has been deleted, and Note
2 to entry has been modified to reference conflict of interest instead of bribery risk and the last sentence has
been deleted.]
3.17
third party
person or body that is independent of the organization (3.1)
Note 1 to entry: All business associates are third parties, but not all third parties are business associates.
[SOURCE: ISO 37301:2021, 3.30]
3.18
public official
person holding a legislative, administrative or judicial office, whether by appointment, election or succession,
or any person exercising a public function, including for a public agency or public enterprise, or any official
or agent of a public domestic or international organization (3.1), or any candidate for public office
[SOURCE: ISO 37001:2025, 3.26, modified — Note 1 to entry has been deleted.]
4 Understanding conflict of interest
4.1 General
Understanding the origin of personal and organizational conflicts of interest requires understanding the
context of the organization. Certain activities can encourage responsible governance and ethical behaviours
of both personnel and organizations. These activities include identifying, assessing, resolving and
monitoring the conflict of interest.
A conflict of interest can emerge when competing interests develop between an interested party and the
organization.
Conflict of interest can manifest at every level of the organization and generate different impacts depending
on the situation.
Unmanaged conflict of interest can result in compromised decision making and wrongdoing and create
significant adverse impact to an organization's ability to remain true to its purpose and ensure it performs
in alignment with its policies and the objectives. This can result in serious deterioration of the organization’s
reputation and trust.
Considering that conflict of interest can arise without the parties involved being aware, the organization
should develop an appropriate management framework to identify, record and monitor conflict of interest.
The framework should raise awareness of all relevant interested parties and help them to understand the
key characteristics of conflict of interest:
— the nature of the interest;
— the nature of interested parties;
— the conditions that create the conflict of interest;
— the category of the interest.
NOTE A conflict of interest is not in itself a problem, but any conflict of interest is expected to be identified,
assessed, resolved and monitored until reasonable objectivity and impartiality are achieved.

4.2 Nature of interest
4.2.1 General
The organization should ensure that all relevant interested parties are able to identify and characterize
the nature of the interest that can give rise to a conflict of interest situation and how it competes with the
interest of the organization.
The competing interests involved in a situation can be related to a person or another organization. The origin
of the interest can be internal to the organization, e.g. directly related to its policy and the implementations
of its processes, or external to the organization.
The nature of the interest of all relevant interested parties in conflict of interest should be disclosed and
available as documented information.
4.2.2 Personal interest
Personal interest is the most common situation involved in conflict of interest.
Interests of this nature can be external to the organization or internal in relation to the interest related to a
person’s role in the organization.
Both internal and external personal interests can create different types of conflict of interest and affect the
performance of the organization in different ways.
The organization should have the processes to identify the personal interest of interested parties when
necessary. The organization should determine if it is relevant to distinguish between external and internal
interest to effectively identify, manage and resolve the conflict of interest.
The nature of the interest of relevant personnel, business associates or third parties in conflict of interest
should be disclosed and available as documented information.
NOTE Examples of internal and external personal interests can be found in Clause A.1.
4.2.3 Organizational interest
Organizational interests are generally attributed to intangible and tangible assets of an organization and
become relevant in the context of a conflict of interest when the organization appears to have competing
interests.
Organizational interests can manifest themselves in the decision-making process both at the governing
body level, e.g. in a merger or acquisition, and at the operational level, e.g. in client acquisition.
The organization should have the processes to identify and assess organizational interests when necessary
and determine if it is relevant to distinguish between external and internal interest to identify an at-risk
situation and effectively manage and resolve conflict of interest throughout the organization.
The relevant interests of the organization in conflict of interest should be available as documented
information.
NOTE 1 Examples of internal and external organizational interests can be found in Clause A.1.
NOTE 2 Examples of at-risk situations can be found in Clause A.2.
4.3 Category of conflict of interest
4.3.1 General
Conflicts of interest can manifest in three different categories:
— actual;
— apparent;
— potential.
Each category has specific characteristics that influence the severity of the risks, and impacts related to the
conflict of interest. Each category has its own set of characteristics that influence the severity of the risks.
The impact that each category has on the organization can also differ.
The organization should use the category of conflict of interest as an input in the conflict management
process (as set out in Clause 8) to facilitate the development of measures to avoid and/or manage the conflict
of interest.
NOTE Conflict of interest can also be categorized as structural conflict of interest (permanent) and conjunctural
conflict of interest (temporary).
4.3.2 Actual conflict of interest
An actual conflict of interest is a situation in which an interested party has a personal or organizational
interest, which is either directly or indirectly related to X, that can compromise, or interfere with, the ability
to act impartially in carrying out their duties in the best interest of the organization. The conflict of interest
is real and current, or it can have existed at some time in the past.
4.3.3 Apparent conflict of interest
An apparent or perceived conflict of interest is a situation in which an interested party has a personal or
organizational interest, directly or indirectly, that can be reasonably perceived to compromise or interfere
with their ability to act impartially when carrying out their duties in the best interest of the organization,
but this is not in fact the case.
4.3.4 Potential conflict of interest
A potential conflict of interest is a situation in which an interested party has a personal or organizational
interest, directly or indirectly, that can compromise, or interfere with, the ability to act impartially in
carrying out their duties in the best interest of the organization, and can arise in the future if the situation is
left untreated, but there is no actual conflict of interest.
5 Framework
5.1 General
The purpose of the conflict of interest management framework is to integrate the management of conflict of
interest into the organization’s governance framework to support the achievement of governance principles,
the organization’s objectives and governance outcomes as aligned to the organization’s strategic direction.
The effectiveness and performance of the conflict of interest management depend on the level of integration
of the framework into the organization's governance policies and management systems.
The framework is anchored on four key principles and sustained by leadership commitment, appropriate
organizational support and a process for managing conflict of interest.

Figure 1 — Conflict of interest framework
5.2 Principles
5.2.1 General
The principles outlined in Figure 1 provide guidance on the characteristics of effective conflict of interest
management. They should be considered as an essential part of the organizational culture in establishing
the conflict of interest framework and implementing the processes.
5.2.2 Trust
Trust is an important foundation for the success of any organization. Organizations, whether public, private,
profit or non-profit, cannot operate effectively and efficiently with low trust. Trust always affects the two
most important measurable outcomes: the speed of business transactions and the cost of doing business.
When trust in an organization decreases, speed decreases, which automatically affects the cost of doing
business and delivering services, and vice versa.
It is important to understand how the conflict of interest relates to trust. Conflict of interest does not
always equate to corruption, as individuals have a right to private interests in their capacity as citizens with
constitutional rights. Private interests, however, become a problem when the holder of the interest is able to

abuse their power to further their own interests or private relationships at the expense of the interests they
are employed or contracted to serve.
Sometimes the potential for abuse is negated by internal safeguards or is not present at all due to the high
morality of the holder of private interests. This is especially the case with apparent conflicts of interest,
where potential mistrust becomes the actual damage. In such cases, the conflict of interest should be
adequately disclosed and remedies should be implemented to preserve trust. Managing conflict of interest,
even when the potential impact is small, is a critical factor in creating a trustworthy environment. It
promotes a culture of ethics, transparency and integrity and has a positive impact on performance.
Trust is more than an asset; it is critical to organizations at all levels. Therefore, unmanaged conflict of
interest undermines trust and can be even more damaging to the organization than corruption itself.
5.2.3 Integrity
Integrity is rooted in personal behaviour and critical to an ethical culture. Promoting integrity encourages
interested parties at every level to act in good faith. The guidance of this document is the basis for interested
parties to uphold fair business practices and ensure and promote ethical business behaviour.
Organizations should set expectations regarding behaviours, practices and the consequences of non-
compliance and respond appropriately when such a situation occurs. Developing a common vocabulary,
identifying at-risk situations, functions or behaviours and providing regular feedback will increase
awareness and foster continual improvement among personnel and interested parties.
A shared vision and understanding of the concept of integrity strengthens and increases the impact of an
ethical culture.
5.2.4 Transparency
Transparency plays a role in effectively managing conflict of interest and maintaining public trust in various
sectors, including private, public and not-for-profit sector.
Key factors to be considered in the principle of transparency are external transparency, internal
transparency and trade secrets and privacy.
Transparency in conflict of interest helps promote accountability, mitigate the risk of bias and protect
the interests of interested parties. By managing conflict of interest, organizations and interested parties
can maintain trust, credibility and ethical conduct in their decision-making processes. The key aspects of
transparency in conflict of interest are disclosure, policies and procedures, independence and impartiality,
public reporting, measurement and enforcement.
5.2.5 Accountability
Accountability is the obligation a person, group or an organization assumes for the fulfilment of a
responsibility. As a principle of conflict of interest, accountability speaks to upholding the values, tenets and
mission of the organization by the interested parties and the organization itself by:
1) demonstrating alignment with corporate goals through actions and behaviours;
2) having clear roles and responsibilities and defined tasks and targets;
3) knowing, understanding and complying with prescribed procedures, standards and rules;
4) providing an explanation or justification for the fulfilment of their responsibilities;
5) measuring and evaluating progress regularly;
6) reporting on the results of fulfilments;
7) assuming liability for those results and applying consequence management.
Personal accountability starts and ends with the individual taking ownership. It cannot be delegated.

The organization, personnel and interested parties should be accountable for ensuring that their interests
will not conflict with their duties and when they do, that it is formally declared and managed.
6 Leadership
6.1 Leadership and commitment
The organization's governing body and top management should set the tone and demonstrate leadership
and commitment to the conflict of interest management framework and its implementation.
6.2 Policy
The organization should establish a conflict of interest policy appropriate to its type, size and the nature of
its business activities. Special considerations should be given to the applicable local legal framework and
whether the organization is a public or private entity.
The conflict of interest policy should clearly set out how to manage conflict of interest in an organization by
interested parties to mitigate risks.
The policy should be applicable to and binding on all personnel, including the governing body and relevant
interested parties of the organization. The policy should state that all interested parties are expected to
comply with the policy on conflict of interest and breaches will not be tolerated and can lead to remedial,
disciplinary and or other relevant management actions.
6.3 Roles and responsibilities
6.3.1 Governing body
The governing body should:
a) approve the organization’s conflict of interest policy, demonstrate clear commitment to its guidelines
and monitor top management with respect to these;
b) ensure that the organization’s strategic direction and the conflict of interest policy are aligned;
c) ensure that adequate and appropriate resources needed for the effectiveness of conflict of interest
management are allocated and assigned;
d) ensure that conflict of interest is being reported;
e) exercise reasonable oversight over the implementation of the organization’s conflict of interest
management framework by top management and its effectiveness.
If an organization does not have a separate governing body, the activities attributed to it are expected to be
carried out by top management.
6.3.2 Top management
Top management should demonstrate leadership and commitment with respect to the organization’s conflict
of interest guidelines by:
a) establishing the organization’s conflict of interest policy;
b) ensuring that the conflict of interest management framework, including its objectives, are established
and are compatible with the strategic direction of the organization;
c) ensuring that the organization’s conflict of interest policy is documented, accessible, established and
communicated both internally and externally, and encouraging its use;

d) ensuring that the resources for the effective operation of the organization’s conflict of interest
management framework are available, appropriate and deployed;
e) ensuring and supporting that roles and responsibilities are clearly defined and assigned for the effective
operation of the organization’s conflict of interest management framework;
f) ensuring adequate training and awareness of personnel and interested parties on the organization’s
conflict of interest management framework;
g) ensuring the integration of the organization’s conflict of interest management framework into the
organization’s business processes, including other management systems;
h) receiving and reviewing reports on the operation and performance of the organization’s conflict of
interest management framework at planned intervals;
i) ensuring effective remediation management on non-compliance.
7 Support
7.1 Resources
Based on the organization’s size, structure and complexity, the organization should determine and provide
the resources for the establishment, implementation, maintenance and continual improvement of the
conflict of interest management framework.
The resources include but are not limited to human, physical and financial resources.
7.2 Competence
The organization should:
— determine the necessary competence of the interested parties that can affect or be affected by the
conflict of interest framework;
— ensure that personnel responsible for the management of conflict of interest framework are competent
on the basis of appropriate qualifications and/or experience.
7.3 Awareness and training
All relevant interested parties should be aware of:
— the organization's policy and processes relating to conflict of interest management;
— how to recognize and disclose conflict of interest;
— available tools, support and resources related to the conflict of interest management framework.
NOTE Some organizations use different types of documents and policies, such as codes of ethics or ethical
frameworks that are considered as part of the policy and processes.
The organization should provide adequate and appropriate conflict of interest guidelines training for
personnel to enhance their awareness and understanding of the organization’s policy on conflict of interest.
The objective of training is to promote the understanding of personnel and the dynamic evolution of the
organization’s established rules and practices. The training should be conducted by the organizat
...


International
Standard
ISO 37009
First edition
Conflict of interest in
2025-09
organizations — Guidance
Conflits d'intérêts dans les organisations — Recommandations
Reference number
© ISO 2025
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
Contents Page
Foreword .v
Introduction .vi
1 Scope .1
2 Normative references .1
3 Terms and definitions .1
4 Understanding conflict of interest .4
4.1 General .4
4.2 Nature of interest .5
4.2.1 General .5
4.2.2 Personal interest .5
4.2.3 Organizational interest .5
4.3 Category of conflict of interest .5
4.3.1 General .5
4.3.2 Actual conflict of interest .6
4.3.3 Apparent conflict of interest .6
4.3.4 Potential conflict of interest .6
5 Framework .6
5.1 General .6
5.2 Principles .7
5.2.1 General .7
5.2.2 Trust .7
5.2.3 Integrity .8
5.2.4 Transparency . . .8
5.2.5 Accountability .8
6 Leadership . 9
6.1 Leadership and commitment .9
6.2 Policy .9
6.3 Roles and responsibilities .9
6.3.1 Governing body .9
6.3.2 Top management .9
7 Support .10
7.1 Resources .10
7.2 Competence .10
7.3 Awareness and training .10
7.4 Communication .11
8 Process . .11
8.1 General .11
8.2 Identification . 12
8.2.1 General . 12
8.2.2 Identification process . 12
8.2.3 Disclosure . 13
8.3 Assessment . 13
8.3.1 General . 13
8.3.2 Assessment process . 13
8.4 Resolution .14
8.4.1 General .14
8.4.2 Resolution process .14
8.5 Monitoring .14
8.5.1 General .14
8.5.2 Monitoring strategies .14
9 Performance evaluation .15

iii
9.1 Review, assessment and compliance. 15
9.2 Evaluating framework effectiveness . 15
Annex A (informative) Managing conflict of interest .16
Bibliography .20

iv
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO document should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 309, Governance of organizations.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.

v
Introduction
This document provides guidance on understanding conflict of interest and how to identify and manage
it for organizations of all types. Conflict of interest (whether actual, potential or perceived) can obstruct
the objectivity and fairness of any decision-making process. Unmanaged conflict of interest is one of the
key risks contributing to corruption or other types of wrongdoings or contributing to the perception of
wrongdoing or other serious risks.
Though conflict of interest is not necessarily corruption, conflict of interest can adversely impact effective
performance, responsible stewardship and ethical behaviour in an organization or the public.
Therefore, organizations should have an effective conflict of interest management framework in place to
ensure that interested parties declare their conflict of interest in time and it is properly managed. Conflict
of interest is a risk by nature and its management will benefit from a governance, risk management and
compliance framework.
This document provides guidance to organizations on understanding conflict of interest and how to
manage conflict of interest based on the principles of trust, integrity, transparency and accountability. It
distinguishes and provides guidance on dealing with actual, apparent and potential conflict of interest.
Potential benefits to the organization include but are not limited to:
a) mitigating risks related to conflict of interest;
b) promoting good governance outcomes, such as effective performance, responsible stewardship and
ethical behaviour;
c) protecting the reputation and building trust;
d) strengthening the decision-making processes;
e) improving and fostering overall compliance performance.
The conflict-of-interest management framework should be an integral part of management, embedded in
the culture and practices, and tailored to the business processes of the organization. The framework for
managing conflict of interest is outlined in this document.
This document should be read in conjunction with other relevant standards and publications that cover
integrity-related risks including:
— ISO 37000
— ISO 37001
— ISO 37002
— ISO 37003
— ISO 37301
— ISO 37004
— ISO/TS 37008
— ISO 31000
NOTE 1 Guidance for governance of organizations is provided in ISO 37000.
NOTE 2 Requirements for a general compliance management system are specified in ISO 37301.

vi
International Standard ISO 37009:2025(en)
Conflict of interest in organizations — Guidance
1 Scope
This document provides guidance to organizations on how to identify, assess, resolve and monitor conflict of
interest based on the principles of trust, integrity, transparency and accountability.
The guidance in this document is generic and intended to be applicable to all organizations, regardless of
type, size and nature of activity and whether in the public, private or not-for-profit sectors. It distinguishes
between actual, apparent and potential conflict of interest.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
organization
person or group of people that has its own functions with responsibilities, authorities and relationships to
achieve its objectives
Note 1 to entry: The concept of organization includes, but is not limited to, sole-trader, company, corporation, firm,
enterprise, authority, partnership, charity or institution, or part or combination thereof, whether incorporated or not,
public or private.
[SOURCE: ISO 37301:2021, 3.1, modified — Note 2 to entry has been deleted.]
3.2
interested party (preferred term)
stakeholder (admitted term)
person or organization (3.1) that can affect, be affected by or perceive itself to be affected by a decision or
activity.
Note 1 to entry: An interested party can be internal or external to the organization.
[SOURCE: ISO 37001:2025, 3.3]
3.3
personnel
organization's (3.1) directors, officers, employees, temporary staff or workers, and volunteers
[SOURCE: ISO 37001:2025, 3.24, modified — Note 1 to entry and Note 2 to entry have been deleted.]

3.4
governing body
person or group of persons who have ultimate accountability for the whole organization (3.1)
Note 1 to entry: A governing body can be explicitly established in a number of formats including, but not limited to, a
board of directors, supervisory board, sole director, joint and several directors, or trustees.
Note 2 to entry: ISO management system standards make reference to the term “top management” to describe a role
that, depending on the standard and organizational context, reports to, and is held accountable by, the governing body.
Note 3 to entry: Not all organizations, particularly small and medium organizations, have a governing body separate
from top management. In such cases, top management exercises the role of the governing body.
[SOURCE: ISO 37000:2021, 3.3.4, modified — Note 1 to entry has been deleted; Note 3 to entry has been added.]
3.5
governance policy
intentions and direction of an organization (3.1), as formally expressed by its governing body (3.4)
[SOURCE: ISO 37000:2021, 3.2.9]
3.6
top management
person or group of people who directs and controls an organization (3.1) at the highest level
Note 1 to entry: Top management has the power to delegate authority and provide resources within the organization.
[SOURCE: ISO 37301:2021, 3.3, modified — Note 2 to entry and Note 3 to entry have been deleted.]
3.7
risk
effect of uncertainty on objectives
Note 1 to entry: An effect is a deviation from the expected - positive or negative.
Note 2 to entry: Uncertainty is the state, even partial, of deficiency of information related to, understanding or
knowledge of, an event, its consequence, or likelihood.
Note 3 to entry: Risk is often characterized by reference to potential events and consequences, or a combination of these.
Note 4 to entry: Risk is often expressed in terms of a combination of the consequences of an event (including changes
in circumstances) and the associated likelihood of occurrence.
[SOURCE: ISO 37301:2021, 3.7]
3.8
process
set of interrelated or interacting activities that use or transform inputs to deliver a result
Note 1 to entry: Whether the result of a process is called an output, a product or a service depends on the context of
the reference.
[SOURCE: ISO 37301:2021, 3.8]
3.9
documented information
information required to be controlled and maintained by an organization (3.1) and the medium on which it
is contained
Note 1 to entry: Documented information can be in any format and media and from any source.
[SOURCE: ISO 37301:2021, 3.10, modified — Note 2 to entry deleted]

3.10
effectiveness
extent to which planned activities are realized and planned results achieved
[SOURCE: ISO 37301:2021, 3.13]
3.11
performance
measurable result
Note 1 to entry: Performance can relate either to quantitative or qualitative findings.
Note 2 to entry: Performance can relate to managing activities, processes (3.8), products, services, systems or
organizations (3.1).
[SOURCE: ISO 37301:2021, 3.11]
3.12
continual improvement
recurring activity to enhance performance (3.11)
[SOURCE: ISO 37301:2021, 3.12]
3.13
conflict of interest
situation in which an interested party has personal interest or organizational interest, directly or indirectly,
that can compromise or interfere with the ability to act impartially in carrying out their duties in the best
interest of the organization
Note 1 to entry: There can be different types of personal interests: business, financial, family, professional, religious
or political.
Note 2 to entry: Organizational interest relates to the interests of an organization or part of an organization (e.g. team
or department) rather than an individual.
3.14
measurement
process (3.8) to determine a value
[SOURCE: ISO 37301:2021, 3.19]
3.15
monitoring
determining the status of a system, a process (3.8) or an activity
Note 1 to entry: To determine the status, there can be a need to check, supervise or critically observe.
[SOURCE: ISO 37301:2021, 3.20]
3.16
business associate
external party with whom the organization (3.1) has, or plans to establish, some form of business relationship
Note 1 to entry: Business associate includes but is not limited to clients, customers, joint ventures, joint venture
partners, consortium partners, outsourcing providers, contractors, consultants, sub-contractors, suppliers, vendors,
advisors, agents, distributors, representatives, intermediaries and investors. This definition is deliberately broad.
Note 2 to entry: Different types of business associate pose different types and degrees of conflict of interest (3.13)risk
(3.7), and an organization will have differing degrees of ability to influence different types of business associate.
Note 3 to entry: Reference to "business" in this document can be interpreted broadly to mean those activities that are
relevant to the purposes of the organization's existence.

[SOURCE: ISO 37001:2025, 3.25, modified — The last sentence in Note 1 to entry has been deleted, and Note
2 to entry has been modified to reference conflict of interest instead of bribery risk and the last sentence has
been deleted.]
3.17
third party
person or body that is independent of the organization (3.1)
Note 1 to entry: All business associates are third parties, but not all third parties are business associates.
[SOURCE: ISO 37301:2021, 3.30]
3.18
public official
person holding a legislative, administrative or judicial office, whether by appointment, election or succession,
or any person exercising a public function, including for a public agency or public enterprise, or any official
or agent of a public domestic or international organization (3.1), or any candidate for public office
[SOURCE: ISO 37001:2025, 3.26, modified — Note 1 to entry has been deleted.]
4 Understanding conflict of interest
4.1 General
Understanding the origin of personal and organizational conflicts of interest requires understanding the
context of the organization. Certain activities can encourage responsible governance and ethical behaviours
of both personnel and organizations. These activities include identifying, assessing, resolving and
monitoring the conflict of interest.
A conflict of interest can emerge when competing interests develop between an interested party and the
organization.
Conflict of interest can manifest at every level of the organization and generate different impacts depending
on the situation.
Unmanaged conflict of interest can result in compromised decision making and wrongdoing and create
significant adverse impact to an organization's ability to remain true to its purpose and ensure it performs
in alignment with its policies and the objectives. This can result in serious deterioration of the organization’s
reputation and trust.
Considering that conflict of interest can arise without the parties involved being aware, the organization
should develop an appropriate management framework to identify, record and monitor conflict of interest.
The framework should raise awareness of all relevant interested parties and help them to understand the
key characteristics of conflict of interest:
— the nature of the interest;
— the nature of interested parties;
— the conditions that create the conflict of interest;
— the category of the interest.
NOTE A conflict of interest is not in itself a problem, but any conflict of interest is expected to be identified,
assessed, resolved and monitored until reasonable objectivity and impartiality are achieved.

4.2 Nature of interest
4.2.1 General
The organization should ensure that all relevant interested parties are able to identify and characterize
the nature of the interest that can give rise to a conflict of interest situation and how it competes with the
interest of the organization.
The competing interests involved in a situation can be related to a person or another organization. The origin
of the interest can be internal to the organization, e.g. directly related to its policy and the implementations
of its processes, or external to the organization.
The nature of the interest of all relevant interested parties in conflict of interest should be disclosed and
available as documented information.
4.2.2 Personal interest
Personal interest is the most common situation involved in conflict of interest.
Interests of this nature can be external to the organization or internal in relation to the interest related to a
person’s role in the organization.
Both internal and external personal interests can create different types of conflict of interest and affect the
performance of the organization in different ways.
The organization should have the processes to identify the personal interest of interested parties when
necessary. The organization should determine if it is relevant to distinguish between external and internal
interest to effectively identify, manage and resolve the conflict of interest.
The nature of the interest of relevant personnel, business associates or third parties in conflict of interest
should be disclosed and available as documented information.
NOTE Examples of internal and external personal interests can be found in Clause A.1.
4.2.3 Organizational interest
Organizational interests are generally attributed to intangible and tangible assets of an organization and
become relevant in the context of a conflict of interest when the organization appears to have competing
interests.
Organizational interests can manifest themselves in the decision-making process both at the governing
body level, e.g. in a merger or acquisition, and at the operational level, e.g. in client acquisition.
The organization should have the processes to identify and assess organizational interests when necessary
and determine if it is relevant to distinguish between external and internal interest to identify an at-risk
situation and effectively manage and resolve conflict of interest throughout the organization.
The relevant interests of the organization in conflict of interest should be available as documented
information.
NOTE 1 Examples of internal and external organizational interests can be found in Clause A.1.
NOTE 2 Examples of at-risk situations can be found in Clause A.2.
4.3 Category of conflict of interest
4.3.1 General
Conflicts of interest can manifest in three different categories:
— actual;
— apparent;
— potential.
Each category has specific characteristics that influence the severity of the risks, and impacts related to the
conflict of interest. Each category has its own set of characteristics that influence the severity of the risks.
The impact that each category has on the organization can also differ.
The organization should use the category of conflict of interest as an input in the conflict management
process (as set out in Clause 8) to facilitate the development of measures to avoid and/or manage the conflict
of interest.
NOTE Conflict of interest can also be categorized as structural conflict of interest (permanent) and conjunctural
conflict of interest (temporary).
4.3.2 Actual conflict of interest
An actual conflict of interest is a situation in which an interested party has a personal or organizational
interest, which is either directly or indirectly related to X, that can compromise, or interfere with, the ability
to act impartially in carrying out their duties in the best interest of the organization. The conflict of interest
is real and current, or it can have existed at some time in the past.
4.3.3 Apparent conflict of interest
An apparent or perceived conflict of interest is a situation in which an interested party has a personal or
organizational interest, directly or indirectly, that can be reasonably perceived to compromise or interfere
with their ability to act impartially when carrying out their duties in the best interest of the organization,
but this is not in fact the case.
4.3.4 Potential conflict of interest
A potential conflict of interest is a situation in which an interested party has a personal or organizational
interest, directly or indirectly, that can compromise, or interfere with, the ability to act impartially in
carrying out their duties in the best interest of the organization, and can arise in the future if the situation is
left untreated, but there is no actual conflict of interest.
5 Framework
5.1 General
The purpose of the conflict of interest management framework is to integrate the management of conflict of
interest into the organization’s governance framework to support the achievement of governance principles,
the organization’s objectives and governance outcomes as aligned to the organization’s strategic direction.
The effectiveness and performance of the conflict of interest management depend on the level of integration
of the framework into the organization's governance policies and management systems.
The framework is anchored on four key principles and sustained by leadership commitment, appropriate
organizational support and a process for managing conflict of interest.

Figure 1 — Conflict of interest framework
5.2 Principles
5.2.1 General
The principles outlined in Figure 1 provide guidance on the characteristics of effective conflict of interest
management. They should be considered as an essential part of the organizational culture in establishing
the conflict of interest framework and implementing the processes.
5.2.2 Trust
Trust is an important foundation for the success of any organization. Organizations, whether public, private,
profit or non-profit, cannot operate effectively and efficiently with low trust. Trust always affects the two
most important measurable outcomes: the speed of business transactions and the cost of doing business.
When trust in an organization decreases, speed decreases, which automatically affects the cost of doing
business and delivering services, and vice versa.
It is important to understand how the conflict of interest relates to trust. Conflict of interest does not
always equate to corruption, as individuals have a right to private interests in their capacity as citizens with
constitutional rights. Private interests, however, become a problem when the holder of the interest is able to

abuse their power to further their own interests or private relationships at the expense of the interests they
are employed or contracted to serve.
Sometimes the potential for abuse is negated by internal safeguards or is not present at all due to the high
morality of the holder of private interests. This is especially the case with apparent conflicts of interest,
where potential mistrust becomes the actual damage. In such cases, the conflict of interest should be
adequately disclosed and remedies should be implemented to preserve trust. Managing conflict of interest,
even when the potential impact is small, is a critical factor in creating a trustworthy environment. It
promotes a culture of ethics, transparency and integrity and has a positive impact on performance.
Trust is more than an asset; it is critical to organizations at all levels. Therefore, unmanaged conflict of
interest undermines trust and can be even more damaging to the organization than corruption itself.
5.2.3 Integrity
Integrity is rooted in personal behaviour and critical to an ethical culture. Promoting integrity encourages
interested parties at every level to act in good faith. The guidance of this document is the basis for interested
parties to uphold fair business practices and ensure and promote ethical business behaviour.
Organizations should set expectations regarding behaviours, practices and the consequences of non-
compliance and respond appropriately when such a situation occurs. Developing a common vocabulary,
identifying at-risk situations, functions or behaviours and providing regular feedback will increase
awareness and foster continual improvement among personnel and interested parties.
A shared vision and understanding of the concept of integrity strengthens and increases the impact of an
ethical culture.
5.2.4 Transparency
Transparency plays a role in effectively managing conflict of interest and maintaining public trust in various
sectors, including private, public and not-for-profit sector.
Key factors to be considered in the principle of transparency are external transparency, internal
transparency and trade secrets and privacy.
Transparency in conflict of interest helps promote accountability, mitigate the risk of bias and protect
the interests of interested parties. By managing conflict of interest, organizations and interested parties
can maintain trust, credibility and ethical conduct in their decision-making processes. The key aspects of
transparency in conflict of interest are disclosure, policies and procedures, independence and impartiality,
public reporting, measurement and enforcement.
5.2.5 Accountability
Accountability is the obligation a person, group or an organization assumes for the fulfilment of a
responsibility. As a principle of conflict of interest, accountability speaks to upholding the values, tenets and
mission of the organization by the interested parties and the organization itself by:
1) demonstrating alignment with corporate goals through actions and behaviours;
2) having clear roles and responsibilities and defined tasks and targets;
3) knowing, understanding and complying with prescribed procedures, standards and rules;
4) providing an explanation or justification for the fulfilment of their responsibilities;
5) measuring and evaluating progress regularly;
6) reporting on the results of fulfilments;
7) assuming liability for those results and applying consequence management.
Personal accountability starts and ends with the individual taking ownership. It cannot be delegated.

The organization, personnel and interested parties should be accountable for ensuring that their interests
will not conflict with their duties and when they do, that it is formally declared and managed.
6 Leadership
6.1 Leadership and commitment
The organization's governing body and top management should set the tone and demonstrate leadership
and commitment to the conflict of interest management framework and its implementation.
6.2 Policy
The organization should establish a conflict of interest policy appropriate to its type, size and the nature of
its business activities. Special considerations should be given to the applicable local legal framework and
whether the organization is a public or private entity.
The conflict of interest policy should clearly set out how to manage conflict of interest in an organization by
interested parties to mitigate risks.
The policy should be applicable to and binding on all personnel, including the governing body and relevant
interested parties of the organization. The policy should state that all interested parties are expected to
comply with the policy on conflict of interest and breaches will not be tolerated and can lead to remedial,
disciplinary and or other relevant management actions.
6.3 Roles and responsibilities
6.3.1 Governing body
The governing body should:
a) approve the organization’s conflict of interest policy, demonstrate clear commitment to its guidelines
and monitor top management with respect to these;
b) ensure that the organization’s strategic direction and the conflict of interest policy are aligned;
c) ensure that adequate and appropriate resources needed for the effectiveness of conflict of interest
management are allocated and assigned;
d) ensure that conflict of interest is being reported;
e) exercise reasonable oversight over the implementation of the organization’s conflict of interest
management framework by top management and its effectiveness.
If an organization does not have a separate governing body, the activities attributed to it are expected to be
carried out by top management.
6.3.2 Top management
Top management should demonstrate leadership and commitment with respect to the organization’s conflict
of interest guidelines by:
a) establishing the organization’s conflict of interest policy;
b) ensuring that the conflict of interest management framework, including its objectives, are established
and are compatible with the strategic direction of the organization;
c) ensuring that the organization’s conflict of interest policy is documented, accessible, established and
communicated both internally and externally, and encouraging its use;

d) ensuring that the resources for the effective operation of the organization’s conflict of interest
management framework are available, appropriate and deployed;
e) ensuring and supporting that roles and responsibilities are clearly defined and assigned for the effective
operation of the organization’s conflict of interest management framework;
f) ensuring adequate training and awareness of personnel and interested parties on the organization’s
conflict of interest management framework;
g) ensuring the integration of the organization’s conflict of interest management framework into the
organization’s business processes, including other management systems;
h) receiving and reviewing reports on the operation and performance of the organization’s conflict of
interest management framework at planned intervals;
i) ensuring effective remediation management on non-compliance.
7 Support
7.1 Resources
Based on the organization’s size, structure and complexity, the organization should determine and provide
the resources for the establishment, implementation, maintenance and continual improvement of the
conflict of interest management framework.
The resources include but are not limited to human, physical and financial resources.
7.2 Competence
The organization should:
— determine the necessary competence of the interested parties that can affect or be affected by the
conflict of interest framework;
— ensure that personnel responsible for the management of conflict of interest framework are competent
on the basis of appropriate qualifications and/or experience.
7.3 Awareness and training
All relevant interested parties should be aware of:
— the organization's policy and processes relating to conflict of interest management;
— how to recognize and disclose conflict of interest;
— available tools, support and resources related to the conflict of interest management framework.
NOTE Some organizations use different types of documents and policies, such as codes of ethics or ethical
frameworks that are considered as part of the policy and processes.
The organization should provide adequate and appropriate conflict of interest guidelines training for
personnel to enhance their awareness and understanding of the organization’s policy on conflict of interest.
The objective of training is to promote the understanding of personnel and the dynamic evolution of the
organization’s established rules and practices. The training should be conducted by the organization to
ensure that personnel are competent to fulfil their roles in a manner that is consistent with the conflict
of interest framework of the organization (see Clause 5) and know how to identify, disclose and manage
conflict of interest.
Such training should address the following:
a) the meaning and the classification of conflict of interest;
b) the conflict of interest policy, procedures and management framework;
c) their duties in relation to disclosing and managing conflict of interest;
d) how to identify and deal with conflict of interest, including practical examples of concrete steps to be
taken for resolving the conflict of interest, and how and to whom they should report legitimate concerns;
e) their contributions to the effectiveness of the conflict of interest framework, including the benefits of
disclosing and managing different forms of conflict of interest;
f) the im
...


Norma Internacional
ISO 37009
Primera edición
Conflicto de interés en las
2025-09
organizaciones — Orientación
Conflict of interest in organizations — Guidance
Publicado por la Secretaría Central de ISO en Ginebra, Suiza,
como traducción oficial en español avalada por el Translation
Management Group, que ha certificado la conformidad en
relación con las versiones inglesa y francesa.
Número de referencia
DOCUMENTO PROTEGIDO POR COPYRIGHT
© ISO 2025
Todos los derechos reservados. Salvo que se especifique de otra manera o se requiera en el contexto de su implementación, no
puede reproducirse ni utilizarse ninguna parte de esta publicación bajo ninguna forma y por ningún medio, electrónico o mecánico,
incluidos el fotocopiado, o la publicación en Internet o una Intranet, sin la autorización previa por escrito. La autorización puede
solicitarse a ISO en la siguiente dirección o al organismo miembro de ISO en el país del solicitante.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Publicado en Suiza
Versión en español publicada en 2026
Traducción oficial
ii
Índice Página
Prólogo .v
Prólogo de la versión en español.vi
Introducción .vii
1 Objeto .1
2 Referencias normativas .1
3 Términos y definiciones .1
4 Comprender el conflicto de interés .4
4.1 Generalidades .4
4.2 Naturaleza del interés .5
4.2.1 Generalidades .5
4.2.2 Interés personal .5
4.2.3 Interés de la organización .5
4.3 Categorías de conflictos de interés .6
4.3.1 Generalidades .6
4.3.2 Conflicto de interés real .6
4.3.3 Conflicto de interés aparente .6
4.3.4 Conflicto de interés potencial .6
5 Marco .6
5.1 Generalidades .6
5.2 Principios .7
5.2.1 Generalidades .7
5.2.2 Confianza .8
5.2.3 Integridad .8
5.2.4 Transparencia .8
5.2.5 Rendición de cuentas .9
6 Liderazgo . 9
6.1 Liderazgo y compromiso .9
6.2 Política .9
6.3 Roles y responsabilidades .9
6.3.1 Órgano de gobierno .9
6.3.2 Alta dirección .10
7 Apoyo . 10
7.1 Recursos .10
7.2 Competencia .10
7.3 Toma de conciencia y formación .11
7.4 Comunicación.11
8 Proceso .12
8.1 Generalidades . 12
8.2 Identificación . 12
8.2.1 Generalidades . 12
8.2.2 Proceso de identificación . 12
8.2.3 Divulgación . 13
8.3 Evaluación.14
8.3.1 Generalidades .14
8.3.2 Proceso de evaluación .14
8.4 Resolución .14
8.4.1 Generalidades .14
8.4.2 Proceso de resolución .14
8.5 Seguimiento . 15
8.5.1 Generalidades . 15
8.5.2 Estrategias de seguimiento . 15

Traducción oficial
iii
9 Evaluación del desempeño .15
9.1 Revisión, evaluación y compliance . 15
9.2 Evaluación de la eficacia del marco.16
Anexo A (informativo) Gestión de los conflictos de interés. 17
Bibliografía.21

Traducción oficial
iv
Prólogo
ISO (Organización Internacional de Normalización) es una federación mundial de organismos nacionales
de normalización (organismos miembros de ISO). El trabajo de elaboración de las Normas Internacionales
se lleva a cabo normalmente a través de los comités técnicos de ISO. Cada organismo miembro interesado
en una materia para la cual se haya establecido un comité técnico, tiene el derecho de estar representado
en dicho comité. Las organizaciones internacionales, gubernamentales y no gubernamentales, vinculadas
con ISO, también participan en el trabajo. ISO colabora estrechamente con la Comisión Electrotécnica
Internacional (IEC) en todos los temas de normalización electrotécnica.
En la Parte 1 de las Directivas ISO/IEC se describen los procedimientos utilizados para desarrollar este
documento y aquellos previstos para su mantenimiento posterior. En particular debería tomarse nota de los
diferentes criterios de aprobación necesarios para los distintos tipos de documentos ISO. Este documento
ha sido redactado de acuerdo con las reglas editoriales de la Parte 2 de las Directivas ISO/IEC (véase
www.iso.org/directives).
ISO llama la atención sobre la posibilidad de que la implementación de este documento pueda conllevar el uso
de una o varias patentes. ISO no se posiciona respecto a la evidencia, validez o aplicabilidad de los derechos
de patente reivindicados. A la fecha de publicación de este documento, ISO no había recibido notificación
de que una o varias patentes pudieran ser necesarias para su implementación. No obstante, se advierte a
los usuarios que esta puede no ser la información más reciente, la cual puede obtenerse de la base de datos
de patentes disponible en www.iso.org/patents. ISO no será responsable de la identificación de parte o la
totalidad de dichos derechos de patente.
Cualquier nombre comercial utilizado en este documento es información que se proporciona para comodidad
del usuario y no constituye una recomendación.
Para una explicación de la naturaleza voluntaria de las normas, el significado de los términos específicos de
ISO y las expresiones relacionadas con la evaluación de la conformidad, así como la información acerca de la
adhesión de ISO a los principios de la Organización Mundial del Comercio (OMC) respecto a los Obstáculos
Técnicos al Comercio (OTC), véase www.iso.org/iso/foreword.html.
Este documento ha sido elaborado por el Comité Técnico ISO/TC 309, Gobernanza de las organizaciones.
Cualquier comentario o pregunta sobre este documento deberían dirigirse al organismo nacional de
normalización del usuario. En www.iso.org/members.html se puede encontrar un listado completo de estos
organismos.
Traducción oficial
v
Prólogo de la versión en español
Este documento ha sido traducido por el Grupo de Trabajo Spanish Translation Task Force (STTF) del Comité
Técnico ISO/TC 309, Gobernanza de las organizaciones, en el que participan representantes de los organismos
nacionales de normalización y otras partes interesadas, para lograr la unificación de la terminología en
lengua española en el ámbito de la gobernanza de las organizaciones.
Este documento ha sido validado por el ISO/TMBG/Spanish Translation Management Group (STMG)
conformado por los siguientes países: Argentina, Bolivia, Chile, Colombia, Costa Rica, Cuba, Ecuador, El
Salvador, España, Guatemala, Honduras, República Dominicana, México, Panamá, Paraguay, Perú y Uruguay.

Traducción oficial
vi
Introducción
Este documento ofrece orientación para comprender el conflicto de interés y cómo identificarlo y gestionarlo
en todo tipo de organizaciones. El conflicto de interés (ya sea real, potencial o percibido) puede obstaculizar
la objetividad y la imparcialidad de cualquier proceso de toma de decisiones. El conflicto de interés no
gestionado es uno de los principales riesgos que contribuyen a la corrupción u otros tipos de irregularidades,
o que contribuyen a la percepción de irregularidades u otros riesgos graves.
Aunque el conflicto de interés no es necesariamente corrupción, puede afectar negativamente al desempeño
eficaz, la administración responsable y el comportamiento ético de una organización o del público.
Por lo tanto, las organizaciones deberían contar con un marco eficaz de gestión de los conflictos de interés
para asegurar que las partes interesadas declaren a tiempo sus conflictos de interés y que estos se gestionen
adecuadamente. El conflicto de interés es un riesgo por naturaleza y su gestión se beneficiará de un marco
de gobernanza, de gestión del riesgo y de compliance.
Este documento ofrece orientación a las organizaciones para comprender el conflicto de interés y cómo
gestionarlo basándose en los principios de confianza, integridad, transparencia y rendición de cuentas.
Distingue y ofrece orientación sobre cómo abordar los conflictos de interés reales, aparentes y potenciales.
Entre los posibles beneficios para la organización se incluyen, entre otros, los siguientes:
a) mitigar los riesgos relacionados con los conflictos de interés;
b) promover resultados de buena gobernanza, como un desempeño eficaz, una administración responsable
y un comportamiento ético;
c) proteger la reputación y generar confianza;
d) fortalecer los procesos de toma de decisiones;
e) mejorar y fomentar el desempeño general en materia de compliance.
El marco de gestión de los conflictos de interés debería ser una parte integral de la gestión, estar integrado
en la cultura y las prácticas, y adaptarse a los procesos de negocio de la organización. En este documento se
describe el marco para la gestión de los conflictos de interés.
Este documento debería leerse junto con otras normas y publicaciones pertinentes que tratan los riesgos
relacionados con la integridad, entre ellas:
— ISO 37000
— ISO 37001
— ISO 37002
— ISO 37003
— ISO 37301
— ISO 37004
— ISO/TS 37008
— ISO 31000
NOTA 1 La Norma ISO 37000 proporciona orientación para la gobernanza de las organizaciones.
NOTA 2 Los requisitos para un sistema general de gestión del compliance se especifican en la Norma ISO 37301.

Traducción oficial
vii
Norma Internacional ISO 37009:2025(es)
Conflicto de interés en las organizaciones — Orientación
1 Objeto
Este documento ofrece orientación a las organizaciones sobre cómo identificar, evaluar, resolver y realizar el
seguimiento de los conflictos de interés basándose en los principios de confianza, integridad, transparencia
y rendición de cuentas.
La orientación que se ofrece en este documento es genérica y está pensada para ser aplicable a todas las
organizaciones, independientemente de su tipo, tamaño y naturaleza de actividad, y de si pertenecen al sector
público, privado o sin fines de lucro. Distingue entre conflictos de interés reales, aparentes y potenciales.
2 Referencias normativas
No hay referencias normativas en este documento.
3 Términos y definiciones
Para los fines de este documento, se aplican los términos y definiciones siguientes:
ISO e IEC mantienen bases de datos terminológicas para su utilización en normalización en las siguientes
direcciones:
— Plataforma de búsqueda en línea de ISO: disponible en https:// www .iso .org/ obp
— Electropedia de IEC: disponible en https:// www .electropedia .org/
3.1
organización
persona o grupo de personas que tiene sus propias funciones con responsabilidades, autoridades y relaciones
para el logro de sus objetivos
Nota 1 a la entrada: El concepto de organización incluye, entre otros, un trabajador independiente, compañía,
corporación, firma, empresa, autoridad, sociedad, organización benéfica o institución, o una parte o combinación de
estas, ya estén constituidas o no, públicas o privadas.
[FUENTE: ISO 37301:2021, 3.1, modificado — Se ha eliminado la Nota 2 a la entrada.]
3.2
parte interesada
persona u organización (3.1) que puede afectar, verse afectada o percibirse afectada por una decisión o
actividad
Nota 1 a la entrada: Una parte interesada puede ser interna o externa a la organización.
[FUENTE: ISO 37001:2025, 3.3]
3.3
personal
directores, funcionarios, empleados, trabajadores temporales y voluntarios de la organización (3.1)
[FUENTE: ISO 37001:2025, 3.24, modificado — Se han eliminado la Nota 1 y la Nota 2 a la entrada.]

Traducción oficial
3.4
órgano de gobierno
persona o grupo de personas que tienen la rendición de cuentas final de toda la organización (3.1)
Nota 1 a la entrada: Un órgano de gobierno puede establecerse explícitamente en varios formatos, que incluyen, entre
otros, directorio, consejo directivo, directores individuales, directorio como conjunto o individualmente o directivos
o administradores.
Nota 2 a la entrada: Las normas de sistema de gestión ISO hacen referencia al término "alta dirección" para describir
un rol que, según la norma y el contexto organizacional, reporta o es responsable ante el órgano de gobierno.
Nota 3 a la entrada: No todas las organizaciones, en particular las pequeñas y medianas, tienen un órgano de gobierno
independiente de la alta dirección. En tales casos, la alta dirección ejerce la función del órgano de gobierno.
[FUENTE: ISO 37000:2021, 3.3.4, modificado — Se ha eliminado la Nota 1 a la entrada; se ha añadido la
Nota 3 a la entrada.]
3.5
política de gobernanza
intenciones y dirección de una organización (3.1), como las expresa formalmente por su órgano de gobierno
(3.4)
[FUENTE: ISO 37000:2021, 3.2.9]
3.6
alta dirección
persona o grupo de personas que dirigen y controlan una organización (3.1) al más alto nivel
Nota 1 a la entrada: La alta dirección tiene el poder de delegar autoridad y proporcionar recursos dentro de la
organización.
[FUENTE: ISO 37301:2021, 3.3, modificado — Se han eliminado la Nota 2 y la Nota 3 a la entrada.]
3.7
riesgo
efecto de la incertidumbre sobre los objetivos
Nota 1 a la entrada: Un efecto es una desviación de lo esperado, ya sea positiva o negativa.
Nota 2 a la entrada: Incertidumbre es el estado, incluso parcial, de deficiencia de información relacionada con la
comprensión o conocimiento de un evento, su consecuencia o su probabilidad.
Nota 3 a la entrada: Con frecuencia el riesgo se caracteriza por referencia a eventos potenciales (como se define en la
ISO Guide 73) y consecuencias (como se define en la ISO Guide 73) , o a una combinación de estos.
Nota 4 a la entrada: Con frecuencia el riesgo se expresa en términos de una combinación de las consecuencias de un
evento (incluidos los cambios de las circunstancias) y la probabilidad (como se define en la ISO Guide 73) de que
ocurra.
[FUENTE: ISO 37301:2021, 3.7]
3.8
proceso
conjunto de actividades interrelacionadas o que interactúan, que utilizan o transforman elementos de
entrada para obtener resultados
Nota 1 a la entrada: Que el resultado de un proceso se denomine salida, producto o servicio depende del contexto de
referencia.
[FUENTE: ISO 37301:2021, 3.8]
Traducción oficial
3.9
información documentada
información que una organización (3.1) tiene que controlar y mantener, y el medio en el que está contenida
Nota 1 a la entrada: La información documentada puede estar en cualquier formato y medio, y provenir de cualquier
fuente.
[FUENTE: ISO 37301:2021, 3.10, modificado — Se ha eliminado la Nota 2 a la entrada]
3.10
eficacia
grado en el que se realizan las actividades planificadas y se logran los resultados planificados
[FUENTE: ISO 37301:2021, 3.13]
3.11
desempeño
resultado medible
Nota 1 a la entrada: El desempeño se puede relacionar con hallazgos cuantitativos o cualitativos.
Nota 2 a la entrada: El desempeño se puede relacionar con actividades de gestión, procesos (3.8), productos, servicios,
sistemas u organizaciones (3.1).
[FUENTE: ISO 37301:2021, 3.11]
3.12
mejora continua
actividad recurrente para mejorar el desempeño (3.11)
[FUENTE: ISO 37301:2021, 3.12]
3.13
conflicto de interés
situación en la que una parte interesada tiene un interés personal u organizacional, directa o indirectamente,
que puede comprometer o interferir con su capacidad para actuar de manera imparcial en el desempeño de
sus funciones, en el mejor interés de la organización
Nota 1 a la entrada: Puede haber diferentes tipos de intereses personales: de negocio, financieros, familiares,
profesionales, religiosos o políticos.
Nota 2 a la entrada: El interés organizacional se refiere a los intereses de una organización o parte de una organización
(por ejemplo, un equipo o departamento) y no a los de un individuo.
3.14
medición
proceso (3.8) para determinar un valor
[FUENTE: ISO 37301:2021, 3.19]
3.15
seguimiento
determinación del estado de un sistema, un proceso (3.8) o una actividad
Nota 1 a la entrada: Para determinar el estado, puede ser necesario verificar, supervisar u observar de forma crítica.
[FUENTE: ISO 37301:2021, 3.20]

Traducción oficial
3.16
socio de negocios
parte externa con la que la organización (3.1) tiene, o planifica establecer, algún tipo de relación comercial
Nota 1 a la entrada: Socio de negocios incluye, pero no se limita a clientes, consumidores, alianzas empresariales,
socios de alianzas empresariales, miembros de un consorcio, proveedores externos, contratistas, consultores,
subcontratistas, proveedores, vendedores, asesores, agentes, distribuidores, representantes, intermediarios e
inversores. Esta definición es deliberadamente amplia.
Nota 2 a la entrada: Diferentes tipos de socios de negocios plantean diferentes tipos y grados de riesgo (3.7) de conflicto
de interés (3.13), y una organización tendrá diferentes grados de capacidad para influir en los diferentes tipos de socios
de negocio.
Nota 3 a la entrada: La referencia a “negocio” en este documento puede interpretarse en sentido amplio para significar
aquellas actividades que son relevantes a los efectos de la existencia de la organización.
[FUENTE: ISO 37001:2025, 3.25, modificado — Se ha eliminado la última frase de la Nota 1 a la entrada y
se ha modificado la Nota 2 a la entrada para hacer referencia al conflicto de interés en lugar del riesgo de
soborno, y se ha eliminado la última frase.]
3.17
tercera parte
persona u organismo independiente de la organización (3.1)
Nota 1 a la entrada: Todos los socios de negocio son terceras partes, pero no todas las terceras partes son socios de
negocio.
[FUENTE: ISO 37301:2021, 3.30]
3.18
funcionario público
toda persona que ocupe un cargo legislativo, administrativo o judicial, por designación, elección o como
sucesor, o cualquier persona que ejerza una función pública, incluso para un organismo público o una
empresa pública, o cualquier funcionario o agente de una organización (3.1) pública local o internacional, o
cualquier candidato a un cargo público
[FUENTE: ISO 37001:2025, 3.26, modificado — Se ha eliminado la Nota 1 a la entrada.]
4 Comprender el conflicto de interés
4.1 Generalidades
Para comprender el origen de los conflictos de interés personales y organizacionales es necesario
comprender el contexto de la organización. Ciertas actividades pueden fomentar la gobernanza responsable
y los comportamientos éticos tanto del personal como de las organizaciones. Estas actividades incluyen
identificar, evaluar, resolver y realizar el seguimiento del conflicto de interés.
Un conflicto de interés puede surgir cuando se desarrollan intereses contrapuestos entre una parte
interesada y la organización.
El conflicto de interés puede manifestarse en todos los niveles de la organización y generar diferentes
impactos según la situación.
Un conflicto de interés no gestionado puede dar lugar a una toma de decisiones comprometida y a
irregularidades, y crear un impacto significativo adverso en la capacidad de una organización para
mantenerse fiel a su propósito y asegurar que actúa alineado con sus políticas y objetivos. Esto puede dar
lugar a un grave deterioro de la reputación y la confianza en la organización.
Teniendo en cuenta que pueden surgir conflictos de interés sin que las partes implicadas sean conscientes de
ello, la organización debería desarrollar un marco de gestión adecuado para identificar, registrar y realizar

Traducción oficial
el seguimiento de los conflictos de interés. El marco debería crear conciencia en todas las partes interesadas
pertinentes y ayudarles a comprender las características clave de los conflictos de interés:
— la naturaleza del interés;
— la naturaleza de las partes interesadas;
— las condiciones que crean el conflicto de interés;
— la categoría del interés.
NOTA Un conflicto de interés no es en sí mismo un problema, pero se espera que cualquier conflicto de interés se
identifique, evalúe, resuelva y se le realice seguimiento hasta que se logre una objetividad e imparcialidad razonables.
4.2 Naturaleza del interés
4.2.1 Generalidades
La organización debería asegurarse de que todas las partes interesadas pertinentes sean capaces de
identificar y caracterizar la naturaleza del interés que puede dar lugar a una situación de conflicto de interés
y cómo compite con el interés de la organización.
Los intereses en conflicto implicados en una situación pueden estar relacionados con una persona u otra
organización. El origen del interés puede ser interno a la organización, por ejemplo, directamente relacionado
con su política y la implementación de sus procesos, o externo a la organización.
La naturaleza del interés de todas las partes interesadas pertinentes en el conflicto de interés debería ser
revelada y estar disponible como información documentada.
4.2.2 Interés personal
El interés personal es la situación más común en la que se produce un conflicto de interés.
Los intereses de esta naturaleza pueden ser externos a la organización o internos en relación con el interés
vinculado al rol de una persona en la organización.
Tanto los intereses personales internos como los externos pueden crear diferentes tipos de conflicto de
interés y afectar al desempeño de la organización de diferentes maneras.
La organización debería contar con procesos para identificar los intereses personales de las partes
interesadas cuando sea necesario. La organización debería determinar si es pertinente distinguir entre
intereses externos e internos para identificar, gestionar y resolver eficazmente los conflictos de interés.
La naturaleza de los intereses del personal pertinente, los socios de negocio o terceras partes en conflicto de
interés debería divulgarse y estar disponible como información documentada.
NOTA Se pueden encontrar ejemplos de intereses personales internos y externos en el Capítulo A.1.
4.2.3 Interés de la organización
Los intereses de la organización se atribuyen generalmente a los activos intangibles y tangibles de una
organización y cobran relevancia en el contexto de un conflicto de interés cuando la organización parece
tener intereses contrapuestos.
Los intereses de la organización pueden manifestarse en el proceso de toma de decisiones tanto a nivel del
órgano de gobierno, por ejemplo, en una fusión o adquisición, como a nivel operativo, por ejemplo, en la
captación de clientes.
La organización debería contar con procesos para identificar y evaluar los intereses organizacionales cuando
sea necesario y determinar si es pertinente distinguir entre intereses externos e internos para identificar
una situación de riesgo y gestionar y resolver eficazmente los conflictos de interés en toda la organización.

Traducción oficial
Los intereses pertinentes a la organización en materia de conflictos de interés deberían estar disponibles
como información documentada.
NOTA 1 Se pueden encontrar ejemplos de intereses organizacionales internos y externos en el Capítulo A.1.
NOTA 2 Se pueden encontrar ejemplos de situaciones de riesgo en el Capítulo A.2.
4.3 Categorías de conflictos de interés
4.3.1 Generalidades
Los conflictos de interés pueden manifestarse en tres categorías diferentes:
— real;
— aparente;
— potencial.
Cada categoría tiene características específicas que influyen en la gravedad de los riesgos y en los impactos
relacionados con el conflicto de interés. Cada categoría tiene su propio conjunto de características que
influyen en la gravedad de los riesgos. El impacto que cada categoría tiene en la organización también puede
variar.
La organización debería utilizar la categoría de conflicto de interés como entrada al proceso de gestión de
los conflictos (tal y como se establece en el Capítulo 8) para facilitar el desarrollo de medidas destinadas a
evitar y/o gestionar el conflicto de interés.
NOTA El conflicto de interés también se puede clasificar como conflicto de interés estructural (permanente) y
conflicto de interés coyuntural (temporal).
4.3.2 Conflicto de interés real
Un conflicto de interés real es una situación en la que una parte interesada tiene un interés personal
u organizacional, relacionado directa o indirectamente con X, que puede comprometer o interferir en su
capacidad para actuar de manera imparcial en el desempeño de sus funciones en el mejor interés de la
organización. El conflicto de interés es real y actual, o puede haber existido en algún momento en el pasado.
4.3.3 Conflicto de interés aparente
Un conflicto de interés aparente o percibido es una situación en la que una parte interesada tiene un interés
personal u organizacional, en forma directa o indirecta, que puede percibirse razonablemente como algo
que compromete o interfiere en su capacidad para actuar de manera imparcial al desempeñar sus funciones
en el mejor interés de la organización, pero que en realidad no es así.
4.3.4 Conflicto de interés potencial
Un conflicto de interés potencial es una situación en la que una parte interesada tiene un interés personal u
organizacional, directa o indirectamente, que puede comprometer o interferir en su capacidad para actuar
de manera imparcial en el desempeño de sus funciones en el mejor interés de la organización, y que puede
surgir en el futuro si la situación no se resuelve, pero no existe un conflicto de interés actual.
5 Marco
5.1 Generalidades
El objetivo del marco de gestión de los conflictos de interés es integrar la gestión de los conflictos de interés
en el marco de gobernanza de la organización para apoyar el cumplimiento de los principios de gobernanza,

Traducción oficial
los objetivos de la organización y los resultados de gobernanza, en consonancia con la dirección estratégica
de la organización.
La eficacia y el desempeño de la gestión de los conflictos de interés dependen del nivel de integración del
marco en las políticas de gobernanza y los sistemas de gestión de la organización.
El marco se basa en cuatro principios clave y se sustenta en el compromiso del liderazgo, el apoyo
organizacional adecuado y un proceso para la gestión de los conflictos de interés.
Figura 1 — Marco de los conflictos de interés
5.2 Principios
5.2.1 Generalidades
Los principios descritos en la Figura 1 proporcionan orientación sobre las características de una gestión
eficaz de los conflictos de interés. Deberían considerarse como una parte esencial de la cultura organizacional
a la hora de establecer el marco de los conflictos de interés e implementar los procesos.

Traducción oficial
5.2.2 Confianza
La confianza es una base importante para el éxito de cualquier organización. Las organizaciones, ya sean
públicas, privadas, con o sin fines de lucro, no pueden funcionar de manera eficaz y eficiente con un bajo nivel
de confianza. La confianza siempre afecta a los dos resultados medibles más importantes: la velocidad de las
transacciones de negocio y el costo de hacer negocios. Cuando la confianza en una organización disminuye,
la velocidad disminuye, lo que automáticamente afecta al costo de hacer negocios y prestar servicios, y
viceversa.
Es importante comprender cómo se relaciona el conflicto de interés con la confianza. El conflicto de interés
no siempre equivale a corrupción, ya que las personas tienen derecho a tener intereses privados en su
calidad de ciudadanos con derechos constitucionales. Sin embargo, los intereses privados se convierten
en un problema cuando quien los tiene puede abusar de su poder para promover sus propios intereses o
relaciones privadas a expensas de los intereses para los cuales fue empleado o contratado.
A veces, el potencial de abuso se ve neutralizado por salvaguardias internas o no existe en absoluto debido a
la elevada moralidad del titular de los intereses privados. Este es especialmente el caso de los conflictos de
interés aparentes, en los que la desconfianza potencial se convierte en un daño real. En tales casos, el conflicto
de interés debería revelarse adecuadamente y deberían aplicarse medidas correctivas para preservar la
confianza. La gestión de los conflictos de interés, incluso cuando su impacto potencial es pequeño, es un
factor crítico para crear un entorno de confianza. Promueve una cultura de ética, transparencia e integridad
y tiene un impacto positivo en el desempeño.
La confianza es más que un activo; es fundamental para las organizaciones a todos los niveles. Por lo tanto,
los conflictos de interés no gestionados socavan la confianza y pueden ser incluso más perjudiciales para la
organización que la propia corrupción.
5.2.3 Integridad
La integridad se basa en el comportamiento personal y es fundamental para una cultura ética. Promover la
integridad anima a las partes interesadas de todos los niveles a actuar de buena fe. Las directrices de este
documento constituyen la base para que las partes interesadas mantengan prácticas de negocio justas y
aseguren y promuevan un comportamiento de negocio ético.
Las organizaciones deberían establecer expectativas en cuanto a comportamientos, prácticas y consecuencias
del incumplimiento, y responder de manera adecuada cuando se produzca una situación de este tipo. El
desarrollo de un vocabulario común, la identificación de situaciones, funciones o comportamientos de riesgo
y la retroalimentación periódica aumentarán la toma de conciencia y fomentarán la mejora continua entre el
personal y las partes interesadas.
Una visión y una comprensión compartidas del concepto de integridad fortalecen y aumentan el impacto de
una cultura ética.
5.2.4 Transparencia
La transparencia desempeña un papel importante en la gestión eficaz de los conflictos de interés y en el
mantenimiento de la confianza pública en diversos sectores, incluidos el privado, el público y el sin fines de
lucro.
Los factores clave que deben tenerse en cuenta en el principio de transparencia son la transparencia externa,
la transparencia interna y los secretos comerciales y la privacidad.
La transparencia en los conflictos de interés ayuda a promover la rendición de cuentas, mitigar el riesgo de
parcialidad y proteger los intereses de las partes interesadas. Mediante la gestión de los conflictos de interés,
las organizaciones y las partes interesadas pueden mantener la confianza, la credibilidad y la conducta ética
en sus procesos de toma de decisiones. Los aspectos clave de la transparencia en los conflictos de interés
son la divulgación, las políticas y procedimientos, la independencia e imparcialidad, la información pública,
la medición y el cumplimiento.

Traducción oficial
5.2.5 Rendición de cuentas
La rendición de cuentas es la obligación que asume una persona, un grupo o una organización para el
cumplimiento de una responsabilidad. Como principio de conflicto de interés, la rendición de cuentas se
refiere al mantenimiento de los valores, principios y misión de la organización por parte de las partes
interesadas y de la propia organización mediante:
1) la demostración de la alineación con los objetivos corporativos a través de acciones y comportamientos;
2) la existencia de roles y responsabilidades claras y tareas y objetivos definidos;
3) el conocimiento, la comprensión y el cumplimiento de los procedimientos, normas y reglas establecidos;
4) la provisión de una explicación o justificación del cumplimiento de sus responsabilidades;
5) la medición y la evaluación del progreso de forma regular;
6) la información acerca de los resultados del cumplimiento;
7) la asunción de la responsabilidad de esos resultados y aplicar la gestión de consecuencias.
La rendición de cuentas personal comienza y termina con la asunción de responsabilidad por parte del
individuo. No se puede delegar.
La organización, el personal y las partes interesadas deberían ser responsables de asegurar que sus intereses
no entren en conflicto con sus obligaciones y, cuando esto ocurra, que se declare y gestione formalmente.
6 Liderazgo
6.1 Liderazgo y compromiso
El órgano de gobierno y la alta dirección de la organización deberían marcar la pauta y demostrar liderazgo
y compromiso con el marco de gestión de los conflictos de interés y su implementación.
6.2 Política
La organización debería establecer una política de conflictos de interés adecuada al tipo, tamaño y naturaleza
de sus actividades de negocio. Se debería prestar especial atención al marco jurídico local aplicable y a si la
organización es una entidad pública o privada.
La política de conflictos de interés debería establecer claramente cómo deben gestionar los conflictos de
interés las partes interesadas de una organización para mitigar los riesgos.
La política debería ser aplicable y vinculante para todo el personal, incluidos el órgano de gobierno y las
partes interesadas pertinentes de la organización. La política debería establecer que se espera que todas las
partes interesadas la cumplan y que no se tolerarán las infracciones, las cuales pueden dar lugar a medidas
correctivas, disciplinarias u otras medidas administrativas pertinentes.
6.3 Roles y responsabilidades
6.3.1 Órgano de gobierno
El órgano de gobierno debería:
a) aprobar la política de conflicto de interés de la organización, demostrar un compromiso claro con sus
directrices y realizar el seguimiento a la alta dirección en lo que respecta a las mismas;
b) asegurar que la dirección estratégica de la organización y la política de conflicto de interés estén
alineadas;
Traducción oficial
c)
...