Code of Conduct legal requirements featured image showing a male compliance officer reviewing a printed Code of Business Ethics and Conduct at a conference table, with a 2x2 stat grid on the right panel showing SOX Section 406, FAR 52.203-13, USSG Chapter 8, and NLRA Section 7 compliance frameworks.

What Makes a Code of Conduct Legally Enforceable? Key Elements and Pitfalls

LAW: Code of Conduct Compliance
What Makes a Code of Conduct Legally Enforceable? Key Elements and Pitfalls
A Code of Conduct is not just a values statement. In the right circumstances, it functions as a contractual document, a disciplinary framework, and a component of a company’s legal compliance obligations under securities law, federal contracting requirements, and anti-harassment statutes. This article explains the legal elements that make a Code of Conduct enforceable, which employers must have one, and the drafting and implementation mistakes that undermine its legal weight.
Legal Disclaimer
This article provides educational information about Code of Conduct legal requirements and enforceability. It does not constitute legal advice. Requirements vary significantly by industry, employer size, jurisdiction, and regulatory framework. Consult qualified legal counsel for guidance specific to your organisation’s situation.
SOX
Mandatory for Public Companies
Section 406 of the Sarbanes-Oxley Act requires public companies to disclose whether they have adopted a code of ethics for senior financial officers. Companies that have not must explain why. The SEC’s implementing rules define minimum required content for the code.
Source: SEC | SOX Section 406 Rules
FAR
Federal Contractors
Federal Acquisition Regulation 52.203-13 requires contractors with contracts valued at $6 million or more to implement a Code of Business Ethics and Conduct, display it to employees, and maintain a hotline for reporting violations. These requirements are a contract term, not merely a recommendation.
Source: FAR | FAR 52.203-13
USSG
Sentencing Mitigation
The US Sentencing Guidelines Chapter 8 treats an effective compliance and ethics program, which typically includes a Code of Conduct, as a mitigating factor in organisational sentencing. Organisations with documented, implemented programs may receive significantly reduced fines following a conviction.
Source: USSC | USSG Chapter 8

Law Summary: The Legal Frameworks That Govern Codes of Conduct

There is no single federal statute that requires all employers to maintain a Code of Conduct. Instead, the legal obligation arises from several overlapping frameworks depending on the employer’s type, size, and regulatory context. Understanding which frameworks apply to your organisation is the first step to building a Code that satisfies its legal obligations rather than simply its cultural aspirations.

Sarbanes-Oxley Act (Public Companies)
SOX Section 406 requires public companies to disclose whether they have a code of ethics for their principal executive officer, principal financial officer, and principal accounting officer. The SEC’s rules define minimum required content: honest and ethical conduct, full disclosure in SEC filings, compliance with laws, and accountability for adherence. Companies that do not have a code must explain why.
Federal Acquisition Regulation (Federal Contractors)
FAR 52.203-13 applies to government contractors with contracts valued above $6 million and lasting more than 120 days. Required elements include a written Code of Business Ethics and Conduct, an employee awareness program, an internal control system for compliance, and a mechanism for employees to report violations anonymously without fear of retaliation.
US Sentencing Guidelines (All Organisations)
Chapter 8 of the USSG provides that organisations convicted of a federal offense can receive reduced fines if they had an effective ethics and compliance program in place before the offense occurred. The program must include standards of conduct, training, and a reporting mechanism. A Code of Conduct is a core element of meeting this standard.
Anti-Harassment Law and Title VII
Under Faragher v. Boca Raton (1998) and Burlington Industries v. Ellerth (1998), employers can raise an affirmative defence against vicarious liability for supervisory harassment if they exercised reasonable care to prevent and correct harassment. A Code of Conduct with an anti-harassment policy, a reporting mechanism, and documented training is central to this defence.

Who Must Have a Code of Conduct

Employer Type
Applicable Requirement
Obligation Level
Public companies (SEC-registered)
SOX Section 406 / SEC Rules
Mandatory (disclose or explain)
Federal contractors (contracts over $6M, over 120 days)
FAR 52.203-13
Mandatory (contract term)
Healthcare organisations (Medicare/Medicaid)
OIG Compliance Program Guidance
Strongly recommended; required for some
Financial institutions (FINRA members)
FINRA Rules 3110, 4511
Mandatory under FINRA rules
All other private employers
No general federal mandate
Best practice; liability risk without one

Applicable Standards and Regulatory Basis

Several regulatory bodies have issued specific guidance on Code of Conduct content and structure. These are not identical: the SOX framework focuses on financial integrity and disclosure, FAR focuses on ethics in government contracting, and the USSG framework is the broadest, covering any organisation subject to federal criminal prosecution. Most employers who need a legally robust Code will need to satisfy elements from more than one framework.

Key Regulatory References
SOX Section 406 / 17 CFR 229.406: SEC rules implementing SOX require public companies to disclose their code of ethics or explain its absence. The code must cover honest conduct, conflicts of interest, full disclosure, compliance with laws, and prompt internal reporting of violations.
FAR 52.203-13: Requires federal contractors to implement a written Code of Business Ethics and Conduct, make it available to employees and agents, maintain an awareness program, and establish an anonymous reporting hotline.
USSG Chapter 8, Section 8B2.1: Defines the elements of an effective compliance and ethics program for sentencing purposes. Requires standards and procedures to prevent criminal conduct, high-level oversight, employee training, and mechanisms for reporting without fear of retaliation.
EEOC Guidance / Title VII: Anti-harassment policies integrated into the Code of Conduct, combined with training and reporting mechanisms, support the affirmative defence established in Faragher and Ellerth. The EEOC’s guidance on harassment prevention recommends a clear policy, multiple reporting channels, and documented training.

Key Definitions

Code of Conduct
A written document establishing the standards of behaviour expected of employees, contractors, and other parties acting on behalf of an organisation. It may function as an employment policy, a component of a compliance program, or in some contexts a contractual document incorporated by reference into an employment agreement.
Code of Ethics
Under SOX and SEC rules, a Code of Ethics is a specific subset of the broader Code of Conduct, focused on integrity in financial reporting, conflict of interest management, and compliance with applicable laws. The SEC definition covers principal executive and financial officers specifically. The terms Code of Conduct and Code of Ethics are sometimes used interchangeably but have distinct meanings in a regulatory context.
Effective Compliance Program (USSG)
Under USSG Chapter 8, an effective compliance and ethics program has seven elements: standards and procedures, high-level oversight, due diligence in hiring, communication and training, monitoring and auditing, consistent enforcement, and response to detected problems. A Code of Conduct is a foundation element but is not sufficient alone to meet the USSG standard.
Affirmative Defence (Faragher/Ellerth)
An affirmative defence is a legal argument that, if proven, defeats or limits the plaintiff’s claim even if the underlying facts are not disputed. Under the Supreme Court’s 1998 decisions, employers can raise an affirmative defence in supervisory harassment cases by showing they exercised reasonable care to prevent the harassment and that the employee unreasonably failed to use the employer’s preventive or corrective mechanisms. A documented anti-harassment policy in the Code of Conduct is central to this defence.

Employer Responsibilities: What Makes a Code Legally Enforceable

The legal enforceability of a Code of Conduct does not come from the document itself. It comes from how the document is adopted, communicated, maintained, and enforced. A Code of Conduct that is well-written but sits on an intranet page without training, consistent enforcement, or documented acknowledgement has limited legal weight when tested.

1
Written acknowledgement from every covered employee
Employees and contractors subject to the Code should sign an acknowledgement confirming they received it, read it, understood it, and agree to comply. Without this, an employer cannot demonstrate that the employee was on notice of the prohibited conduct. Courts and arbitrators have dismissed disciplinary actions that were based on a Code the employee was never asked to acknowledge.
2
At-will disclaimer where applicable
In at-will employment states, a Code of Conduct can inadvertently create an implied contract if it uses mandatory language about progressive discipline or guarantees of employment. Include a clear disclaimer stating that the Code does not modify the at-will employment relationship and does not constitute a contract of employment. Review language with employment counsel before finalising.
3
Consistent enforcement
A Code enforced selectively or not enforced at all creates two problems. The first is a discrimination or retaliation claim when one employee is disciplined under the Code and another is not for similar conduct. The second is the erosion of the Code’s legal value as a compliance program element. Document every Code violation investigation and its outcome, including cases where no action was taken and why.
4
A functioning reporting mechanism
The DOJ’s evaluation framework for compliance programs specifically asks whether reporting channels are accessible, whether employees actually use them, and whether reports generate appropriate investigations. A hotline or ethics inbox that exists on paper but does not receive reports, or that receives reports that go uninvestigated, does not satisfy this requirement. Track report volume, investigation timelines, and outcomes.

Employee Rights Under Code of Conduct Frameworks

Employees Have the Right To
Employers Cannot
Receive a copy of the Code and an explanation of its requirements before being asked to acknowledge it
Require employees to sign an acknowledgement of a Code they were never given access to read
Report Code violations without fear of retaliation (protected under SOX, Dodd-Frank, and anti-retaliation provisions of many statutes)
Retaliate against employees for good-faith reports of ethics or compliance violations, including internal reports
Collective action on workplace conditions even where conduct could appear to conflict with the Code (NLRA protections)
Discipline employees for NLRA-protected concerted activity, even if characterised as a Code violation
Confidentiality protections for reports made to anonymous ethics hotlines (where provided)
Use Code violations as a pretext for disciplining an employee for protected activity (whistleblowing, union organising, EEOC complaints)

Common Violations and Legal Pitfalls

Most Common Code of Conduct Legal Failures
Overbroad confidentiality and social media clauses NLRA violation risk
The NLRB has repeatedly found that Code of Conduct provisions broadly prohibiting employees from discussing wages, working conditions, or employer policies with colleagues or the public violate Section 7 of the NLRA. Many standard confidentiality and social media clauses drafted before NLRB guidance evolved are now legally non-compliant. Review and narrow these provisions.
Implied contract language in progressive discipline sections Employment contract risk
Language such as “employees will receive a written warning before termination” or “termination is the final step in our disciplinary process” can be interpreted as a contractual limitation on the employer’s right to terminate at will. Courts in some states have enforced such provisions as implied contracts. Use discretionary language: “may include” rather than “will include.”
Failure to train and document training Compliance program defence failure
A Code of Conduct that exists without documented training is a document, not a compliance program. Under both the USSG and the DOJ’s evaluation framework, training and communication are mandatory elements. Maintain dated records of who was trained, on what content, and by what method. This documentation is what gets produced to regulators and in litigation.
Selectively enforcing Code provisions Discrimination and retaliation exposure
Selective enforcement generates discrimination claims when similarly situated employees are treated differently. It also undermines the Code’s value as a compliance program element, since regulators will examine whether the program was actually followed rather than merely documented. Treat enforcement decisions as legal decisions and document the reasoning.
Source: NLRB | NLRB Employee Rights

Penalties and Consequences for Non-Compliance

The penalties for Code of Conduct failures depend entirely on which regulatory framework was violated. A public company that fails to disclose its code of ethics under SOX faces SEC enforcement action and potential deregistration consequences. A federal contractor that fails to implement the required Code under FAR 52.203-13 risks contract termination for default and suspension or debarment from future federal contracting. An employer that lacks a functional anti-harassment policy and reporting mechanism, and faces a supervisory harassment claim, cannot raise the Faragher/Ellerth affirmative defence and will face full vicarious liability for the harassment.

Under the USSG, the difference between an organisation with a documented effective compliance program and one without can translate to a culpability score multiplier ranging from 0.05 to 4.0, applied to a base fine. At significant fine levels, this multiplier difference can amount to millions of dollars. The USSG’s sentencing mitigation framework was designed specifically to create a financial incentive for organisations to invest in compliance programs before violations occur.

Compliance Checklist

Document Integrity
Code covers all required topics for applicable regulatory frameworks (SOX, FAR, USSG)
At-will disclaimer included where applicable
Confidentiality and social media clauses reviewed for NLRA compliance
Progressive discipline language is discretionary, not mandatory
Implementation and Training
All employees and applicable contractors sign acknowledgement form
Training documented with dates, attendees, and content covered
Annual review and re-acknowledgement process in place
Code available in languages of the workforce where applicable
Reporting and Enforcement
Anonymous reporting mechanism in place and accessible
Investigations are documented with findings and outcomes
Enforcement is consistent and tracked across similar violations
Anti-retaliation provisions are communicated and enforced

Key Takeaways

The document is the least important part
Courts, regulators, and the DOJ’s own published guidance are consistent on this point: the existence of a Code of Conduct document matters far less than whether it was communicated, trained on, consistently enforced, and supported by a functional reporting mechanism. A well-drafted Code that sits unimplemented provides minimal legal protection and may actually create liability by establishing standards the organisation then demonstrably failed to follow.
NLRA compliance is a frequently overlooked requirement
The most common legal problem with existing Codes of Conduct that have not been recently reviewed is overbroad confidentiality, social media, or conduct clauses that restrict NLRA Section 7 rights. The NLRB has been active in this area and its standards have evolved. Any Code drafted before approximately 2019 should be reviewed against current NLRB guidance before being re-issued to employees.
Which framework applies determines what must be in the Code
A private employer with no federal contracts and no securities listing has no mandatory Code of Conduct requirement, though best practice and tort liability exposure make having one advisable. A public company, a federal contractor, and a FINRA member firm each face different mandatory content requirements. Building one Code that tries to satisfy all frameworks simultaneously is possible but requires legal review to ensure each framework’s specific elements are addressed.

Frequently Asked Questions

Can a Code of Conduct be used to terminate an employee without a prior warning?
In at-will states, generally yes for a first violation. The exception is when the Code itself uses mandatory progressive discipline language, which some courts have treated as an implied contract. Use permissive language (“may include”) rather than mandatory language (“will include”) and include an explicit at-will disclaimer.

Does the Code of Conduct need to cover contractors and vendors, not just employees?
For some regulatory frameworks, yes. FAR 52.203-13 requires the Code to apply to the contractor’s agents as well as employees. Under the USSG effective compliance program standard, the organisation is expected to use due diligence to prevent criminal conduct by persons “associated with the organisation,” which includes agents and contractors. SOX requirements are focused on officers and directors. Review your specific framework to determine whether your Code’s scope extends to non-employees, and ensure the acknowledgement process covers all covered persons.

What should a Code of Conduct’s anti-harassment section include to support the Faragher/Ellerth affirmative defence?
To support the affirmative defence, the anti-harassment section should clearly define prohibited conduct, identify multiple reporting channels (not solely the direct supervisor), provide a process for investigating complaints, include anti-retaliation protections, and state the consequences for violations. The employer must then actually conduct training on the policy, document that training, and demonstrate that the reporting mechanisms functioned in practice. The Supreme Court’s decisions require both a reasonable prevention and correction effort and that reporting channels be accessible and usable.

How often should a Code of Conduct be updated?
At minimum, review the Code annually and update it when material changes occur: new NLRB or EEOC guidance, changes in the organisation’s regulatory status (a federal contract award, a public offering), acquisition of a new business unit, or following any compliance incident that revealed a coverage gap. The DOJ’s evaluation framework specifically asks whether compliance programs are updated in response to lessons learned. Codes drafted before approximately 2019 should be reviewed against current NLRB guidance on confidentiality and social media clauses before being re-issued, as the NLRB’s standards in this area have changed considerably. A Code that has not been reviewed in five or more years is unlikely to reflect current legal expectations.

Government and Regulatory Sources

Related VelSafe Articles

Building a Code That Functions as a Compliance Program

The organisations that benefit most from their Codes of Conduct are not necessarily those with the most comprehensive documents. They are those that communicate the Code consistently, train employees on its requirements, investigate reports when they come in, enforce the Code without favouritism, and update it when the regulatory environment or the organisation changes. Those practices are what regulators examine, what courts weigh, and what determines whether the Code provides legal protection or creates additional liability. Find more compliance and workplace safety resources at velsafe.com.

Comments are closed.