01Why "policy" deserves its own chapter

Compliance texts often treat policy as plumbing — necessary infrastructure, but not the interesting part. The interesting part, the story goes, is culture, or leadership, or enforcement. Policy is just paperwork.

That view misses something important. A policy is the most durable artifact of an organization's ethical commitments. Individuals retire, leaders change, cultures shift — but a well-written policy stays. It is discoverable by a regulator, a journalist, or a new employee three years from now. It is the thing a company points to when it says "we told people what was expected."

And for that reason, it is also the thing a company is judged against when the gap between stated values and actual behavior becomes visible. The U.S. Department of Justice's FCPA guidance (FCPA = Foreign Corrupt Practices Act, the U.S. law against bribing foreign officials), the UK Sentencing Council's Corporate Manslaughter and Homicide Act guidance, Japan's Ministry of Economy, Trade and Industry guidelines on corporate governance — all evaluate compliance programs partly by asking one question: did you have written policies, and were they adequate?

This chapter is about what makes a policy adequate: in structure, in content, and in the way it connects to the rest of the compliance system.

02The three-layer structure: principle → policy → SOP

It helps to think of governance documents as a three-layer stack.

Layer 1

Principles / Code of Ethics

Abstract commitments ("we act with integrity", "we put patients first"). Stable over decades. Aspirational by design. Cannot be violated technically — they can only be honored or ignored.

Layer 2

Policies

Rules that translate principle into direction. "All transfers of value to healthcare professionals must be approved in advance and disclosed." (A transfer of value, often shortened to ToV, is any payment or benefit a company gives — a fee, a meal, travel.) Specific enough to be violated. Updated every 2–3 years or when law changes.

Layer 3

SOPs / Work Instructions

SOPs (Standard Operating Procedures) are step-by-step manuals for specific tasks. "Submit the ToV form at least 10 business days before the event; attach the vendor quote and the speaker's CV." Operational. May change with systems or roles.

Relationship

The directionality matters

Policy must be derivable from principle — if you cannot explain why a rule exists in principled terms, the rule is probably wrong. SOPs must be derivable from policy — if a procedure conflicts with its parent policy, the procedure must change.

This hierarchy is not just theoretical tidiness. When a regulator or a court evaluates your program, they trace the chain: is this procedure consistent with that policy? Is that policy consistent with a stated principle? Gaps in the chain — places where no policy covers a situation, or where a policy contradicts another — are finding magnets.

The practical implication: policy owners must know both layers above and below them. A policy that is logically consistent with principle but operationally impossible to implement produces SOPs that quietly deviate — and quiet deviation is how scandals begin.

03Code of Conduct as instrument — how Pfizer, J&J, and MSD approach it

The Code of Conduct sits at the top of the policy stack, closest to principle. In most large pharma companies it is also the document most employees actually encounter — often annually, via mandatory training and certification.

What makes a Code of Conduct effective as an instrument rather than a formality? Three features stand out when you compare the public versions that major companies publish.

Coverage without exhaustiveness

Pfizer's Code covers a wide range of situations — scientific integrity, promotion, anti-corruption, privacy, conflicts of interest — but does so in relatively plain language, deferring detail to supporting policies. J&J's equivalent emphasizes the four-credo hierarchy (patients, employees, communities, shareholders in that order) as an explicit decision framework, not just a values statement. MSD's Code (MSD is the trade name used outside North America for what is sold as Merck in the United States and Canada) is notable for its scenario-based structure: many sections include "how this applies in practice" vignettes — short worked examples — that help employees connect an abstract rule to a concrete situation.

The common thread: a Code that tries to be complete fails. One that provides a framework for thinking — and points to where to find more specific rules — succeeds.

Accountability architecture

Codes that work include a clear accountability structure: who sets the policy, who enforces it, who employees can go to when they are uncertain. This is not bureaucratic decoration. An employee who does not know who owns a rule will not follow it consistently.

Explicit scope for third parties

Modern Codes explicitly extend their obligations to contractors, distributors, and agents — the supply chain and commercial partners through whom a violation is just as likely to originate as from an internal employee. This has been a focus of DOJ enforcement guidance since at least 2012.

04Conflict of Interest policy — Sunshine, transparency, and KOL transactions

No policy area in pharma generates more day-to-day friction than conflict of interest (a conflict of interest, sometimes shortened to COI, is any situation where a personal interest could distort a professional judgment). The reason is structural: pharma's business model requires genuine scientific partnerships with the physicians who prescribe its products — including KOLs (key opinion leaders, the influential expert physicians a field looks to). Those partnerships — speaker programs, advisory boards, research collaborations, educational grants — are also the primary vectors through which improper influence can flow.

The Sunshine Act and its descendants

In the United States, the Physician Payments Sunshine Act (enacted as part of the Affordable Care Act in 2010) requires drug and device manufacturers to report annually to the Centers for Medicare & Medicaid Services (CMS, the U.S. government agency that runs public health insurance) any payment or transfer of value to covered recipients (physicians, teaching hospitals, certain advanced practice practitioners). The data is published in the Open Payments database, freely searchable by anyone.

The Sunshine Act did not make these payments illegal. It made them visible. Visibility, the theory goes, allows physicians, patients, and institutions to evaluate whether a relationship has colored a clinical recommendation. The empirical evidence on whether disclosure changes behavior is mixed — but disclosure has become a baseline expectation internationally, with analogous transparency schemes in the EU (the EFPIA Disclosure Code — EFPIA is the European pharma industry federation), the UK (the ABPI, the British pharma industry association), Australia, and Japan.

Japan's framework: the JPMA Transparency Guidelines

In Japan, the Japan Pharmaceutical Manufacturers Association (JPMA — the major industry body, whose Japanese name is 日本製薬工業協会) publishes Transparency Guidelines that member companies follow. Unlike the U.S. Sunshine Act, Japan's system is self-regulatory rather than statutory: companies disclose transfers of value to healthcare professionals and institutions on their own websites, in a standardized format, annually. The disclosed categories include research fees, consulting fees, speaker honoraria, manuscript fees, and expenses (travel, accommodation, meals).

The absence of a statutory mandate does not make the obligation less real. JPMA membership carries reputational weight, and deviation from the Guidelines is visible to regulators, institutional procurement committees, and media. In practice, Japan subsidiaries of global companies operate under both the JPMA Guidelines and their parent company's global disclosure policy — and the more stringent of the two governs.

What a Conflict of Interest policy must do

Fair Market Value (FMV): The cornerstone concept in managing payments to physicians. Payment to a physician for services must reflect what those services would fetch in an arm's-length transaction (= a deal struck on fair, neutral terms, as if between unrelated parties with no favoritism) — not what it costs to secure the physician's goodwill. Most large companies use third-party FMV databases calibrated by specialty, service type, and geography. Using FMV consistently is both a legal protection and an ethical discipline: it forces the question "are we paying for a genuine service, or for access?"

05Anti-bribery and anti-corruption — four frameworks, one standard

Bribery in pharma takes many forms: a payment to a government procurement official to put a drug on the national formulary, a "consulting" arrangement with a hospital administrator who controls which drugs get stocked, a travel sponsorship for a physician that is really a reward for past prescribing. The legal frameworks that address this are international, overlapping, and — for global companies — all simultaneously applicable.

FCPA — the U.S. Foreign Corrupt Practices Act

Enacted in 1977 and a major enforcement priority since the mid-2000s, the FCPA prohibits U.S. persons and companies, and foreign companies listed on U.S. exchanges, from paying bribes to foreign government officials to obtain or retain business. "Government official" in the pharma context includes physicians employed at state hospitals. That category covers most hospital doctors in many countries, including China and much of Europe — so an ordinary gift to a hospital physician abroad can fall under the law. FCPA enforcement against pharma companies (Novartis, Teva, Pfizer and other major pharma companies have faced investigations) has made the law familiar across the industry globally.

UK Bribery Act

The UK Bribery Act 2010 goes further in two ways. First, it covers commercial bribery — paying a private-sector employee to do something favorable — not only bribes of government officials. Second, it creates a strict-liability offense for failing to prevent bribery: a company is guilty if a person "associated" with it (which includes third-party agents and distributors) pays a bribe on its behalf, unless the company can demonstrate it had "adequate procedures" in place. "Adequate procedures" has become a term of art (= a phrase with a fixed, specialized legal meaning): the UK Ministry of Justice has published six principles (proportionate procedures, top-level commitment, risk assessment, due diligence, communication, monitoring and review) against which a program is evaluated.

Japan — Unfair Competition Prevention Act

Japan addresses bribery of foreign officials through the Unfair Competition Prevention Act (不正競争防止法, Fusei Kyoso Boshi Ho), which was amended in 1998 to comply with the OECD Anti-Bribery Convention (the OECD is the Organisation for Economic Co-operation and Development, a group of mostly wealthy democracies that sets shared policy standards). It prohibits payments to foreign public officials in connection with international transactions. Domestically, a separate framework — the Act against Unjustifiable Premiums and Misleading Representations and various medical institution procurement rules — governs relationships with Japanese healthcare professionals and public hospitals.

JPMA Code — transfer-of-value provisions

The JPMA Code of Practice (自主規範) includes specific provisions on what member companies may and may not offer to healthcare professionals: limits on meal expenses, prohibitions on entertainment unconnected to a genuine scientific purpose, requirements that speaker fees be calibrated to FMV. These provisions overlap with the Transparency Guidelines and are enforced via the JPMA's self-governance mechanism — companies that violate the Code may be subject to JPMA review and, in serious cases, public disclosure of findings.

FrameworkJurisdiction / ScopeKey feature FCPAU.S. (+ foreign issuers on U.S. exchanges)Covers foreign government officials; long extraterritorial reach; major DOJ/SEC enforcement history UK Bribery ActUK (+ companies doing business in UK)Covers commercial bribery; "failure to prevent" strict liability; requires adequate procedures Japan UCPAJapan (foreign official bribery)OECD-aligned; narrower domestic scope than FCPA/UK Act JPMA CodeJapan (member companies)Self-regulatory; ToV caps; FMV discipline; Transparency Guidelines linkage

For a Japan subsidiary of a global pharma company, all four frameworks are simultaneously operative. A global anti-bribery policy must satisfy the most stringent applicable standard — which in practice usually means UK Bribery Act "adequate procedures" as the design benchmark, with FCPA enforcement history as the risk-calibration guide.

06Data Integrity policy — ALCOA+, GxP, and research honesty

If anti-bribery policy protects the boundary between the company and external parties, data integrity policy protects the boundary between what the company knows and what it says it knows. That boundary — between internal data and reported data — is where regulatory systems place enormous trust. When it breaks, the consequences are severe: warning letters, import alerts, consent decrees, and in serious cases, criminal prosecution.

ALCOA+ as the organizing framework

The FDA (the U.S. Food and Drug Administration, the American drug regulator) and the EMA (the European Medicines Agency, the EU's drug regulator) both use the ALCOA+ acronym to describe the properties of reliable data in GxP-regulated environments (GxP is shorthand for the family of official "Good Practice" standards that protect medicine quality — the x stands in for Manufacturing, Clinical, Laboratory, and so on):

The "+" extends these with Complete, Consistent, Enduring, and Available. These eight properties define what regulators expect data to be. A data integrity policy translates them into organizational requirements: who may amend a record (and how), how audit trails are protected, what happens when a discrepancy is found, and how raw data is retained.

GxP integration

Data integrity requirements apply across all GxP domains — Good Manufacturing Practice (GMP), Good Clinical Practice (GCP), and Good Laboratory Practice (GLP) — though their specific expression differs. In GMP, the focus is on batch records, equipment logs, and environmental monitoring data. In GCP, it is source data at clinical sites, electronic data capture systems, and audit trails in clinical trial management systems. In GLP, it is laboratory notebooks and instrument raw data.

A policy that treats these as separate problems misses the shared risk: in each domain, the temptation is the same — to fix a data point that makes a product look bad, or to reconstruct a record that was not made contemporaneously. A unified data integrity policy states the organization's position on this temptation and the consequences of yielding to it.

Research integrity — beyond GxP

Data integrity in the regulatory-submission sense is well-covered in most pharma Quality Management Systems. Less uniformly covered is research integrity in the broader sense: ghost-writing of publications, selective reporting of clinical data, post-hoc endpoint changes in sponsored trials. These are not always GxP violations — they occur in contexts (medical communications, investigator-sponsored studies) where GxP does not formally apply. But they carry equal or greater reputational risk and have attracted increasing attention from medical journals, academic institutions, and regulators in Europe and the United States.

A complete data integrity policy extends its principles into these contexts explicitly.

07What "implementation" actually means

Writing a policy is the easy part. The gap between a written policy and actual behavior is where most compliance programs fail. Implementation has three components: training, monitoring, and response to violation.

Training

Annual mandatory training is the baseline. It is also, by itself, insufficient. Research on compliance training consistently finds that knowledge gained in a one-hour module decays rapidly and does not reliably change behavior in ambiguous situations — which are the situations that matter.

Effective training supplements the annual module with role-specific, scenario-based learning delivered closer to the moment of need. A newly hired medical affairs manager learns the conflict-of-interest policy not only in new-hire orientation but in a workshop that simulates real advisory board scenarios. A sales manager encounters the anti-bribery policy not only in an e-learning module but in coaching from a compliance business partner before a KOL event.

"Training is not what happens in the classroom. Training is what changes what people do at their desks on Tuesday morning." — a formulation sometimes attributed to behavioral compliance researchers working with DOJ.

Monitoring

Policies require monitoring to be real. Monitoring can be transactional (reviewing every expense report above a threshold, auditing a sample of KOL contracts) or systemic (analyzing payment data for patterns that suggest off-policy behavior, comparing disclosed ToV with contracting records).

The trend in pharma compliance is toward data analytics: using internal data (CRM records, payment databases, travel and expense systems) to identify anomalies that warrant follow-up. This is more scalable than manual review and, when done well, more protective — it catches patterns that individual reviewers miss.

Response to violation

How an organization responds to a policy violation signals, more than any training program, what the organization actually values. The key dimensions:

The seniority trap: The most reliable predictor of a compliance program's credibility is whether senior leaders who violate policy are treated the same as junior employees. When they are not — and in most organizations, they are not — the entire policy framework is devalued. Employees learn what the policy actually means by watching what happens when it is broken, not by reading what it says.

08Particular challenges of Japan subsidiaries

For employees at Japan subsidiaries of global pharma companies — which describes most of the industry in Japan — policy implementation carries a specific set of challenges that deserve separate attention.

Global-parent policy translation

Global policies are written primarily in English and calibrated to the most stringent globally applicable regulatory environment. When translated into Japanese and applied to the Japan business, they encounter three friction points.

Legal framework differences: Japan's regulatory structure for HCP interactions is largely self-regulatory (JPMA Code, company SOPs) rather than statutory (as in the U.S. Sunshine Act). This means compliance requirements are often set internally by the Japan affiliate in dialogue with the parent — and the parent's global policy may be more restrictive than local law requires, or may use concepts (like "government official") that have different scope in Japan than in the U.S.

Cultural context: Japanese business culture places high value on relationship maintenance (関係性, kankesei) and gift-giving as expressions of professional respect. Global anti-bribery and ToV policies that categorically restrict meals and gifts can collide with local professional norms in ways that generate compliance resistance — not because employees are trying to behave corruptly, but because they are trying to navigate a cultural expectation that the global policy does not acknowledge.

Translation ambiguity: Compliance concepts that are clear in English — "transfer of value," "associated person," "adequate procedures" — often lack direct Japanese equivalents. The translation process can introduce ambiguity, or resolve it in ways that the policy authors did not intend. Japan subsidiaries that simply translate the global policy without adaptation often end up with documents that employees cannot use.

Local accountability structures

In global companies, Compliance functions at the Japan subsidiary level typically report to both a local executive and a global compliance leader. This dual reporting line can create tensions when global standards and local business pressures diverge. The Japan Compliance Officer's ability to escalate issues upward — and to be genuinely heard — is a significant factor in whether the policy framework functions or is quietly worked around.

09Three remaining challenges

Even well-designed policy frameworks face structural challenges that have not been fully solved.

Policy proliferation and navigability

Large pharma companies often have dozens of policies, hundreds of SOPs, and layers of guidance documents. Employees facing a real decision in real time frequently cannot navigate this corpus. An employee who cannot find the applicable policy in three minutes will not use it. Policy architecture — how policies are organized, how they reference each other, how they are surfaced at the moment of need — matters as much as policy content.

Third-party reach

The most significant compliance risks in modern pharma increasingly reside outside the direct workforce — in contract research organizations, distributors, co-promotion partners, and patient services vendors. Policies bind employees; they do not automatically bind third parties. Extending policy reach to third parties requires due diligence, contractual obligations, and monitoring — all of which add cost and complexity that organizations tend to underinvest in until after a problem occurs.

The speed of emerging risks

Digital health, AI-assisted clinical decision tools, patient influencer relationships, social media promotional content — these areas are generating compliance questions faster than policy cycles can address them. A policy updated every two years has limited utility in a domain where the risk landscape shifts every six months. Organizations are experimenting with faster-cycle guidance documents and compliance advisory functions that can respond in near-real time — but the tension between the stability that policy requires and the speed that emerging risks demand remains unresolved.

10Connections to other chapters

Policy is not a standalone topic. Its meaning depends on the system it sits inside.

In closing

Policies are the document layer between what an organization believes and what it does. That sentence sounds modest. In practice, it describes something that takes sustained organizational effort to maintain: clear text, consistent training, active monitoring, credible response to violation, and the humility to update when the policy is not working.

The companies that handle policy well are not those with the most pages of documentation. They are those where an employee facing a real ethical decision on a Tuesday morning knows where to look, trusts that the answer is there, and believes that following it will be respected — not worked around by the people above her.

That is the gap this chapter is trying to name. Not between what the policy says and what regulators require. Between what the policy says and what actually happens. Closing that gap is the daily work of compliance.