How to Write a Code of Conduct for Your Business (With Template)

9 min read

Learning how to write a code of conduct is one of the most practical steps a business can take to make its values real. A code of conduct is the document that turns "we act with integrity" into specific, expected behaviour: how people treat each other, how they handle conflicts of interest, and what to do when something is not right. This guide sets out the sections to include, the tone that works, and how to approve and roll it out, with a template structure you can adapt.

Start with why, not rules

Before you draft a single rule, get clear on the purpose. A good code of conduct is not a list of bans; it is a statement of who you are as an organisation and how that shapes daily behaviour. Anchor it in a short set of values, then let the practical guidance flow from them. If you have not yet defined those values, our pillar on what is business ethics is a good starting point, and the ethical decision-making framework gives people a way to reason through the grey areas the code cannot spell out.

The sections to include: a code of conduct template

Most effective codes share a common backbone. Use this as a template and cut or expand sections to fit your size and sector:

  • Opening statement from leadership. A short message from the chief executive or chair explaining why the code exists and that it applies to everyone, including the top.
  • Our values and purpose. The three to five principles the rest of the code rests on.
  • Who the code applies to. Employees, contractors, directors and, where relevant, suppliers and partners.
  • Treating people fairly. Dignity at work, anti-harassment, equality and inclusion, and health and safety.
  • Integrity in business. Conflicts of interest, gifts and hospitality, anti-bribery and corruption, fair competition and accurate records.
  • Protecting assets and information. Data protection and confidentiality, responsible use of company property, and use of IT and social media.
  • Working with the outside world. Honest marketing, responsible sourcing, and environmental and community commitments.
  • Raising concerns. How to speak up, the whistleblowing channel, and a clear no-retaliation promise.
  • Consequences and review. What happens if the code is breached, and when the document is reviewed.

Write it in plain language

The most common mistake is writing a code that reads like a legal contract. If people cannot understand it, they will not use it. Write in plain English, in the second person ("you"), and use short, concrete examples: what a conflict of interest actually looks like, or when a gift crosses the line. A few realistic scenarios do more than a page of abstract principle. Keep it as short as the risks allow; a code people can read and remember beats a long one that lives in a drawer.

Get it approved and owned at the top

A code only carries weight if leadership visibly stands behind it. Have the board or senior leadership formally approve it, and make sure the opening statement is genuinely from them. HR and legal will usually help draft and pressure-test it, but ownership has to sit with the people at the top, who must also be seen to live by it. A code the executive ignores is worse than no code at all, because it teaches everyone that the rules are for show.

Roll it out so people actually use it

Publishing the document is the start, not the finish. Introduce it properly: brief managers first, run short training that walks through the real scenarios, and ask everyone to acknowledge they have read it. Build it into induction for new starters, reference it when relevant decisions come up, and make the speak-up route genuinely easy and safe to use. Then review the code every year or two, and sooner after a major change, dating each version so people know they have the current one.

Done well, a code of conduct becomes the reference point that keeps behaviour consistent as you grow. For the wider system it sits within, see our guide to improving corporate governance. The Institute of Business Ethics also publishes free guidance and real-world examples that are worth reading before you finalise your draft. For more on building an ethical culture, browse E-Business Ethics.

Frequently asked questions

What is the difference between a code of conduct and a code of ethics?

A code of ethics sets out your values and principles at a high level, while a code of conduct translates them into specific expected behaviours and rules. Many organisations combine both in one document, with the values up front and the practical conduct below.

Does a small business need a code of conduct?

Yes, a proportionate one. Even a short code sets shared expectations, protects the business in disputes, and reassures clients and partners. It does not need to be long; it needs to be clear, owned by leadership and actually used.

How long should a code of conduct be?

Long enough to cover the real risks and no longer. For most small and mid-sized firms that is a few pages of plain language. A code people can read and remember beats a lengthy legal document nobody opens.

Who should approve the code of conduct?

The board or senior leadership should formally approve and visibly own it, because a code only carries weight if the top of the organisation stands behind it. Legal or HR usually help draft it, but leadership must adopt it.

How often should a code of conduct be reviewed?

Review it at least every year or two, and sooner after a significant change such as new laws, a merger, or a serious incident. Date each version and record what changed so staff know they are reading the current one.