Ethics & Governance Policy Kit — 6 Policies | People Stack Now

$79.00

Governance policies are the documentation that serious businesses have in place before they need them — not the policies they scramble to create when an investor asks at due diligence or a regulator comes knocking. This kit gives growing businesses the six governance-critical policies that signal organisational maturity and protect against the most serious operational and legal risks.

Six documents: the Anti-Bribery & Corruption Policy (UK Bribery Act s.7 compliant, with gifts and hospitality traffic-light table and gifts register requirement — applicable to any business with UK commercial activity regardless of where it is incorporated), the Conflicts of Interest Policy (covering all six conflict categories with disclosure process, severity framework, and annual declaration form), the Whistleblowing & Protected Disclosure Policy (compliant with the Irish Protected Disclosures Act 2014/2022, UK PIDA, US Dodd-Frank, and AU legislation), the Social Media Policy (covering Company and personal accounts with NLRA Section 7 protection guidance for US employees), the Inventions Policy & Date of Invention Record System (the IP protection infrastructure that technology companies depend on), and the AI Usage Policy (covering the EU AI Act, GDPR, HIPAA, traffic-light use tables, and the AI tool register).

Each policy is written for a business operating across multiple jurisdictions, with inline guidance on the specific legislative requirements that apply in each.

What's included

–  Anti-Bribery & Corruption Policy

–  Conflicts of Interest Policy

–  Whistleblowing & Protected Disclosure Policy

–  Social Media Policy

–  Inventions Policy & Date of Invention Record

–  AI Usage Policy

–  6 documents total

FAQs

Q  Does the UK Bribery Act apply to companies that are not based in the UK?

Yes — and this is the most commonly misunderstood aspect of the Act. Section 7 of the UK Bribery Act 2010 creates a corporate offence for failure to prevent bribery, which applies to any company that carries on business or any part of its business in the United Kingdom — regardless of where the company is incorporated or where the bribery occurred. An Irish company with UK customers, a US company with UK employees, or any business that attends UK trade events or signs UK contracts falls within scope. The only complete defence is having adequate anti-bribery procedures in place. The Anti-Bribery & Corruption Policy in this kit constitutes those procedures.

Q  Is the Whistleblowing Policy legally required?

In Ireland, yes — for organisations with 50 or more employees. The Protected Disclosures (Amendment) Act 2022, which transposes the EU Whistleblower Directive 2019/1937, requires organisations above that threshold to establish formal internal reporting channels and a written policy covering them. This is a legal requirement that came into effect in 2023, not a best practice recommendation. For organisations with fewer than 50 employees in Ireland, it is still strongly recommended. In the UK, while not universally mandated, the Financial Conduct Authority and other regulators require regulated firms to have documented whistleblowing procedures. In the US, Dodd-Frank, SOX, and the False Claims Act each impose whistleblower-related requirements on relevant businesses.

Q  What is the Inventions Policy and does my company need it?

The Inventions Policy establishes that the Company owns inventions made by employees using Company resources, within the scope of their duties, or relating to the Company's business. It also establishes the date-of-invention record system required to preserve and enforce patent rights by competent evidence. Any technology company — software, health tech, medical device, or otherwise — that may want to patent its inventions needs this policy and the accompanying record system in place from early in its development. Patent rights that cannot be established by competent evidence because the record-keeping infrastructure did not exist at the time of invention are patent rights lost.

Q  Why is the AI Usage Policy included in a governance kit rather than an IT or acceptable use bundle?

AI governance is fundamentally an ethics and accountability question, not just an IT security question. The EU AI Act — which entered into force in August 2024 — classifies AI systems used for recruitment, performance monitoring, and employee evaluation as high-risk under Annex III, imposing conformity assessment, transparency, and human oversight obligations. The AI Usage Policy covers not just which tools employees may use and how, but the governance framework for approving AI tools, the accountability principles for AI-generated outputs, and the employment law compliance obligations that arise when AI is used in HR decisions. These are governance questions that belong alongside anti-bribery, conflicts of interest, and whistleblowing — not alongside device security.

Governance policies are the documentation that serious businesses have in place before they need them — not the policies they scramble to create when an investor asks at due diligence or a regulator comes knocking. This kit gives growing businesses the six governance-critical policies that signal organisational maturity and protect against the most serious operational and legal risks.

Six documents: the Anti-Bribery & Corruption Policy (UK Bribery Act s.7 compliant, with gifts and hospitality traffic-light table and gifts register requirement — applicable to any business with UK commercial activity regardless of where it is incorporated), the Conflicts of Interest Policy (covering all six conflict categories with disclosure process, severity framework, and annual declaration form), the Whistleblowing & Protected Disclosure Policy (compliant with the Irish Protected Disclosures Act 2014/2022, UK PIDA, US Dodd-Frank, and AU legislation), the Social Media Policy (covering Company and personal accounts with NLRA Section 7 protection guidance for US employees), the Inventions Policy & Date of Invention Record System (the IP protection infrastructure that technology companies depend on), and the AI Usage Policy (covering the EU AI Act, GDPR, HIPAA, traffic-light use tables, and the AI tool register).

Each policy is written for a business operating across multiple jurisdictions, with inline guidance on the specific legislative requirements that apply in each.

What's included

–  Anti-Bribery & Corruption Policy

–  Conflicts of Interest Policy

–  Whistleblowing & Protected Disclosure Policy

–  Social Media Policy

–  Inventions Policy & Date of Invention Record

–  AI Usage Policy

–  6 documents total

FAQs

Q  Does the UK Bribery Act apply to companies that are not based in the UK?

Yes — and this is the most commonly misunderstood aspect of the Act. Section 7 of the UK Bribery Act 2010 creates a corporate offence for failure to prevent bribery, which applies to any company that carries on business or any part of its business in the United Kingdom — regardless of where the company is incorporated or where the bribery occurred. An Irish company with UK customers, a US company with UK employees, or any business that attends UK trade events or signs UK contracts falls within scope. The only complete defence is having adequate anti-bribery procedures in place. The Anti-Bribery & Corruption Policy in this kit constitutes those procedures.

Q  Is the Whistleblowing Policy legally required?

In Ireland, yes — for organisations with 50 or more employees. The Protected Disclosures (Amendment) Act 2022, which transposes the EU Whistleblower Directive 2019/1937, requires organisations above that threshold to establish formal internal reporting channels and a written policy covering them. This is a legal requirement that came into effect in 2023, not a best practice recommendation. For organisations with fewer than 50 employees in Ireland, it is still strongly recommended. In the UK, while not universally mandated, the Financial Conduct Authority and other regulators require regulated firms to have documented whistleblowing procedures. In the US, Dodd-Frank, SOX, and the False Claims Act each impose whistleblower-related requirements on relevant businesses.

Q  What is the Inventions Policy and does my company need it?

The Inventions Policy establishes that the Company owns inventions made by employees using Company resources, within the scope of their duties, or relating to the Company's business. It also establishes the date-of-invention record system required to preserve and enforce patent rights by competent evidence. Any technology company — software, health tech, medical device, or otherwise — that may want to patent its inventions needs this policy and the accompanying record system in place from early in its development. Patent rights that cannot be established by competent evidence because the record-keeping infrastructure did not exist at the time of invention are patent rights lost.

Q  Why is the AI Usage Policy included in a governance kit rather than an IT or acceptable use bundle?

AI governance is fundamentally an ethics and accountability question, not just an IT security question. The EU AI Act — which entered into force in August 2024 — classifies AI systems used for recruitment, performance monitoring, and employee evaluation as high-risk under Annex III, imposing conformity assessment, transparency, and human oversight obligations. The AI Usage Policy covers not just which tools employees may use and how, but the governance framework for approving AI tools, the accountability principles for AI-generated outputs, and the employment law compliance obligations that arise when AI is used in HR decisions. These are governance questions that belong alongside anti-bribery, conflicts of interest, and whistleblowing — not alongside device security.