Skip to main content
Category: Compliance & Audit

Codes of Conduct

Also known as: Code of Conduct, Conduct Code
Simply put

A code of conduct is a written statement that sets out the standards, values, and rules an organization expects its members to follow. It serves as a foundational document communicating an organization's commitment to responsible practice. In an AI context, such codes may articulate expected behaviors and principles governing how people develop, deploy, or use AI systems.

Formal definition

As commonly defined, a code of conduct is a formal articulation of the norms, rules, responsibilities, and proper practices governing the conduct of an individual, board, or organization, conveying a commitment to responsible practice. It typically functions as a foundational governance document that broadly establishes expectations for behavior, from which more specific policies and procedures may flow. The evidence provided describes codes of conduct as a general organizational governance concept and does not establish a single authoritative definition specific to AI systems or to any particular regulatory framework; readers should note that the scope, enforceability, and content of a given code vary by organization and jurisdiction, and that a code of conduct is a policy instrument that helps set expectations rather than a control that eliminates risk.

Why it matters

Codes of conduct matter because they translate an organization's stated commitment to responsible practice into a written, shared reference point that members are expected to follow. In an AI governance context, a code can articulate the values and expected behaviors that shape how people develop, deploy, or use AI systems, giving individuals and boards a common vocabulary for what the organization considers acceptable conduct. Because a code is typically a foundational document from which more specific policies and procedures may flow, it often functions as the "house" that lower-level rules are built within, helping establish expectations before detailed operational controls are defined.

The practical significance of a code lies in setting and communicating expectations, not in guaranteeing outcomes. A code of conduct is a policy instrument that helps convey a commitment to responsible practice; it is not a control that eliminates risk, and its effectiveness depends heavily on how it is implemented, monitored, and enforced. Professionals should be cautious about treating the existence of a code as evidence that risks are managed, since a written statement of values does not by itself ensure that behavior conforms to it.

The scope, enforceability, and content of any given code vary by organization and by jurisdiction, and the evidence available describes codes of conduct as a general organizational governance concept rather than establishing a single authoritative definition specific to AI systems or to any particular regulatory framework. Readers should therefore interpret a code within its own organizational and legal context rather than assuming a uniform meaning across settings.

Who it's relevant to

Boards and Directors
A code of conduct may set out the rules and conditions around being a board member that each member should be aware of, making it directly relevant to those exercising organizational oversight. Boards often rely on such codes to convey a shared commitment to responsible practice and to establish expectations from which more specific governance measures may follow.
AI Governance and Policy Specialists
Those responsible for AI governance may use a code of conduct as a foundational document that broadly establishes expectations for behavior in developing, deploying, or using AI systems. It is worth noting that the evidence describes codes of conduct as a general governance concept and does not establish a definition specific to AI or to any particular regulatory framework, so specialists should adapt the concept to their own organizational and jurisdictional context.
Compliance and Ethics Professionals
Compliance and ethics functions typically treat the code as the foundational document from which more specific policies and procedures flow. Because a code helps set expectations rather than eliminate risk, these professionals should focus on how it is implemented, monitored, and enforced rather than treating its existence alone as evidence that risks are controlled.

Inside Codes of Conduct

Voluntary Commitments
Codes of conduct are typically voluntary instruments in which organizations or industry participants commit to specified principles or practices for AI development and use. Unlike binding law such as the EU AI Act, adherence is generally self-imposed rather than legally mandated, though in some contexts codes may become referenced by regulators or contractually enforced.
Behavioral and Ethical Principles
They commonly articulate high-level principles—such as transparency, accountability, fairness, and safety—intended to guide the conduct of individuals or entities involved in designing, deploying, or overseeing AI systems. These principles are usually aspirational and require operational controls to become actionable.
Scope and Applicability Provisions
A code typically defines who is bound (for example, employees, member firms, or signatories) and what activities or systems fall within its coverage. Scope may be sector-specific or organization-specific, and the same term can carry different meaning across industries.
Accountability and Oversight Mechanisms
As an element of AI governance, codes often specify roles, escalation paths, or oversight expectations. This addresses organizational structures and accountability rather than the technical measurement of model risk, though the two areas can overlap where a code references model validation or monitoring expectations.
Enforcement and Consequence Provisions
Some codes include mechanisms for monitoring adherence and responding to breaches, which can range from internal disciplinary measures to reputational or membership consequences. The strength of enforcement varies widely and is frequently weaker than that of statutory instruments.

Common questions

Answers to the questions practitioners most commonly ask about Codes of Conduct.

Are codes of conduct legally binding requirements that AI providers must follow?
Not typically in the general sense. As commonly used, a code of conduct is a voluntary instrument that organizations or industry groups adopt to signal commitment to certain practices, rather than a binding legal mandate. Where a specific regulatory framework references codes of conduct, the legal weight depends on that framework and jurisdiction, and should not be assumed to be universal. Absent a clear statutory hook, adherence is generally voluntary, though it may inform expectations, contractual commitments, or reputational assessments.
Does adopting a code of conduct establish an organization's AI governance program?
No. A code of conduct is one component that can support governance, but it is not equivalent to a governance program. AI governance typically encompasses organizational structures, defined accountability, policies, and oversight mechanisms, while a code of conduct usually articulates principles or commitments at a higher level. Treating a code as a substitute for operational controls, roles, and monitoring conflates a statement of intent with the structures needed to implement and enforce it.
How does a code of conduct relate to internal policies and procedures?
A code of conduct generally sits at a higher, principle-oriented level, while policies and procedures translate those principles into specific, actionable requirements. In many organizations the code sets expectations that policies then operationalize, and procedures specify how those policies are executed. Keeping these layers distinct helps clarify which document expresses intent versus which imposes concrete, testable obligations.
Who is typically responsible for maintaining and enforcing a code of conduct?
Responsibility often varies by organization and is not universally assigned to one function. In many governance arrangements, ownership involves a combination of senior leadership or a designated body that approves the code, functions that operationalize it, and oversight or assurance functions that check adherence. Mapping ownership to defined roles helps avoid the common gap where a code exists on paper but no accountable owner monitors or enforces it.
How can adherence to a code of conduct be evidenced or demonstrated?
Because codes are frequently principle-based, demonstrating adherence usually requires linking commitments to more concrete artifacts such as documented policies, records of decisions, training records, or monitoring outputs. Without such linkage, a code can be difficult to audit. Where a specific framework prescribes evidence expectations, those should be followed; otherwise organizations commonly define their own means of demonstrating conformance, and the sufficiency of that evidence can be contested.
When should a code of conduct be reviewed or updated?
As commonly practiced, codes are reviewed periodically and in response to material changes, such as shifts in the organization's use of AI, changes in applicable regulatory expectations, or lessons from incidents. There is no single universally mandated review cycle, so the cadence is typically set by the adopting organization. Treating a code as static risks misalignment with evolving practices and expectations, so a defined review trigger and schedule is generally advisable.

Common misconceptions

A code of conduct is legally binding and carries the same force as regulation.
Codes of conduct are typically voluntary and self-imposed. They generally do not carry the binding legal force of statutes such as the EU AI Act, although in certain contexts they may be referenced by regulators, incorporated into contracts, or become expected practice. Their legal weight should not be assumed and varies by jurisdiction and context.
Adopting a code of conduct is equivalent to having a model risk management program.
A code of conduct is primarily an AI governance instrument concerned with principles, accountability, and organizational conduct. Model risk management—the identification, measurement, monitoring, and control of risks arising from model use—is a distinct discipline. A code may reference or support such practices but does not by itself constitute the validation, monitoring, and control functions of a model risk management framework.
A code of conduct eliminates AI-related risk once adopted.
Codes are measures intended to reduce or manage risk, not to eliminate it. Adherence to stated principles does not guarantee compliance in practice or remove residual risk, which typically persists after controls are applied.

Best practices

Clearly define the scope, applicability, and covered activities so it is unambiguous who is bound and which systems the code addresses.
Translate high-level principles into operational controls and responsibilities rather than leaving them as aspirational statements, and distinguish governance commitments from model risk management activities where both are referenced.
Specify accountability, oversight, and escalation mechanisms so that responsibility for adherence is assigned to identifiable roles.
Establish monitoring and enforcement provisions proportionate to the code's purpose, and be transparent about whether the code is voluntary or contractually binding in a given context.
Align the code with, but do not conflate it against, applicable binding frameworks and voluntary standards, correctly attributing each instrument to its issuing body and jurisdiction.
Review and update the code periodically to reflect evolving regulatory expectations, and avoid presenting proposed or emerging requirements as settled obligations.