Board-ready code of business conduct and ethics for a newly public biopharmaceutical company, consolidating source policies and addressing applicable public-company governance, healthcare-interaction, whistleblower, disclosure, compensation-recovery, conflicts, privacy, and compliance-program requirements, with a drafting memorandum documenting gap resolution and open action items.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-compliance-regulatory --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Compliance Regulatory?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-compliance-regulatory)More formats (shields.io, HTML) on the badges page.
---
name: code-of-business-conduct-ethics-newly-public-biopharma
task_id: corporate-governance/draft-compliance-regulatory
description: Board-ready code of business conduct and ethics for a newly public biopharmaceutical company, consolidating source policies and addressing applicable public-company governance, healthcare-interaction, whistleblower, disclosure, compensation-recovery, conflicts, privacy, and compliance-program requirements, with a drafting memorandum documenting gap resolution and open action items.
activates_for: [planner, solver, checker]
---
# Skill: Code of Business Conduct and Ethics for Newly Public Biopharmaceutical Company
## 1. Subject-matter triage (only if applicable)
- Treat the code as a single, superseding governance document for a newly public life-sciences issuer, not as a patchwork of legacy policies.
- Separate provisions that must bind all personnel from provisions that require enhanced handling for directors, executive officers, finance/accounting leadership, and compliance-sensitive functions.
- Identify any required implementation dependency that is operational rather than textual, such as compliance staffing, hotline/reporting functionality, training, certification, escalation, or board oversight readiness.
- If the source set contains multiple legacy policies, first map them by topic and owner before drafting so overlaps, gaps, and conflicts can be resolved deliberately rather than by compression.
## 2. Failure modes the skill is correcting
- Drafting a code that reads like a generic ethics policy and omits the public-company features that make it board-ready, including waiver governance, disclosure discipline, whistleblower protection, and officer coverage.
- Leaving senior finance and accounting officers outside the express scope of the code or failing to give them heightened obligations for truthful reporting, internal controls, and disclosure integrity.
- Protecting only internal reports while omitting reports to regulators, audit committee visibility, and non-retaliation for good-faith escalation.
- Creating healthcare-interaction language that is too vague to govern meals, speaker programs, consulting, educational support, scientific exchange, or other regulated interactions.
- Failing to reconcile conflicts among source policies, especially where legacy provisions differ on approvals, escalation paths, clawback alignment, confidentiality, or disclosure controls.
- Treating compliance infrastructure as assumed when the record shows a staffing or system dependency that must be flagged as an open implementation item.
- Drafting a memorandum that summarizes themes but does not identify each gap, the governing standard, the resolution chosen, and what remains to be done outside the text.
## 3. Legal frameworks / domain conventions that apply
- Public-company code of ethics/conduct standards require broad application, truthful and complete reporting, compliance with law, conflict escalation, and a defined waiver process for covered persons.
- Exchange-listing governance conventions require a code administered by an identified oversight body, with waiver review and disclosure handling for senior personnel where needed.
- Officer-focused disclosure obligations require enhanced language for principal executive, financial, and accounting personnel on completeness, accuracy, internal controls, and escalation of concerns.
- Whistleblower and anti-retaliation norms require protection for reports made internally and to external regulators, plus anonymous reporting and board-level oversight.
- Healthcare compliance conventions require rules for interactions with healthcare professionals, anti-bribery and anti-kickback guardrails, accurate documentation, fair-market and business-purpose discipline, and review of higher-risk arrangements.
- Transfer-of-value and transparency reporting conventions require employees to preserve records, route information to compliance, and avoid concealment or off-book arrangements.
- Clawback governance requires the code to be consistent with any separately adopted compensation-recovery policy and to flag covered officers and awards without inventing conflicting standards.
- Conflicts and corporate-opportunity conventions require advance disclosure of outside employment, consulting, investments, family relationships, board service, and other divided-loyalty situations.
- Privacy and information-security norms require careful handling of personal data, confidential scientific data, breach escalation, access controls, and monitoring practices consistent with applicable law.
- Board materials conventionally distinguish the operative code from the drafting memorandum, which should record how the code was built, what was harmonized, and what still needs follow-up.
## 4. Analytical scaffolds
- Start with a topic-by-topic source-policy inventory, then consolidate into one hierarchy: purpose, scope, core duties, conflicts, records and disclosure, healthcare interactions, confidentiality and privacy, reporting and investigation, enforcement, waivers, and officer-specific obligations.
- For each source-policy topic, ask four questions: what rule is common across the sources, what conflicts or gaps exist, what rule should control in the new code, and whether the issue can be fixed in text or requires a separate action item.
- Draft each substantive rule with a compliance purpose, a mandatory duty, a reporting or approval channel, and a consequence for noncompliance where appropriate.
- Where the source record is silent on a required governance feature, preserve the silence in the code only if another company document clearly governs it; otherwise flag it in the memorandum as an open item.
- For waiver and exception handling, specify who may approve, what body oversees or receives notice, and whether any special treatment applies to directors or executive officers.
- For officer-specific disclosure discipline, tie the obligation to complete, accurate, timely internal reporting and escalation of doubts, not merely to general honesty language.
- For healthcare-interaction rules, distinguish low-risk ordinary business activities from higher-risk arrangements that need preclearance, legal review, documentation, or enhanced monitoring.
- For privacy and information-security provisions, connect employee duties to practical behaviors: need-to-know access, secure storage, incident escalation, device protection, and cross-border handling where relevant.
- For the drafting memorandum, organize each issue as: source gap or conflict, governing standard, drafting resolution, and follow-up item if the text cannot fully cure it.
## 5. Vertical / structural / temporal relationships
- Draft the code as the stable operative instrument and the memorandum as the temporal record of how the code was assembled from legacy materials.
- Treat compliance leadership readiness and reporting-infrastructure readiness as parallel to, not sequenced after, the code: the code creates obligations that require functioning administration from day one.
- Align the clawback section with any existing compensation-recovery framework so the code does not imply a broader or narrower standard than the company has adopted elsewhere.
- If a waiver or approval path changes by role, place the general rule first and then the officer- or director-specific overlay so the hierarchy is clear.
- If source policies conflict on the same topic, resolve the conflict in the code and explain the choice in the memorandum; do not leave inconsistent parallel obligations in the final text.
## 6. Output structure conventions
- Produce two board-ready Word documents: one operative code and one drafting memorandum.
- The code should read as a standalone, company-wide ethics and conduct standard with a distinct section for enhanced obligations applicable to senior finance and accounting personnel.
- Use conventional governance headings rather than a rubric-like checklist. Typical shapes include purpose/scope, standards of conduct, conflicts, records and disclosure, use of company assets, compliance with law, reporting and investigations, waivers, enforcement, and officer-specific requirements.
- The code should contain clear mandatory language, defined escalation points, and board or committee oversight where governance practice calls for it.
- The memorandum should be concise but complete, and should identify each legacy-policy gap or inconsistency, the controlling authority or governance rationale, the chosen resolution, and any implementation dependency left open.
- End the memorandum with explicit follow-up actions that assign responsibility and timing in practical terms, using roles and milestones rather than abstract suggestions.
- Before finishing, confirm that the operative code is complete and not merely descriptive, and that the memorandum tracks unresolved operational items separately from drafting choices.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!