01Why "policy" deserves its own chapter
Compliance texts often treat policy as plumbing — necessary infrastructure, but not the interesting part. The interesting part, the story goes, is culture, or leadership, or enforcement. Policy is just paperwork.
That view misses something important. A policy is the most durable artifact of an organization's ethical commitments. Individuals retire, leaders change, cultures shift — but a well-written policy stays. It is discoverable by a regulator, a journalist, or a new employee three years from now. It is the thing a company points to when it says "we told people what was expected."
And for that reason, it is also the thing a company is judged against when the gap between stated values and actual behavior becomes visible. The U.S. Department of Justice's FCPA guidance (FCPA = Foreign Corrupt Practices Act, the U.S. law against bribing foreign officials), the UK Sentencing Council's Corporate Manslaughter and Homicide Act guidance, Japan's Ministry of Economy, Trade and Industry guidelines on corporate governance — all evaluate compliance programs partly by asking one question: did you have written policies, and were they adequate?
This chapter is about what makes a policy adequate: in structure, in content, and in the way it connects to the rest of the compliance system.
02The three-layer structure: principle → policy → SOP
It helps to think of governance documents as a three-layer stack.
Principles / Code of Ethics
Abstract commitments ("we act with integrity", "we put patients first"). Stable over decades. Aspirational by design. Cannot be violated technically — they can only be honored or ignored.
Policies
Rules that translate principle into direction. "All transfers of value to healthcare professionals must be approved in advance and disclosed." (A transfer of value, often shortened to ToV, is any payment or benefit a company gives — a fee, a meal, travel.) Specific enough to be violated. Updated every 2–3 years or when law changes.
SOPs / Work Instructions
SOPs (Standard Operating Procedures) are step-by-step manuals for specific tasks. "Submit the ToV form at least 10 business days before the event; attach the vendor quote and the speaker's CV." Operational. May change with systems or roles.
The directionality matters
Policy must be derivable from principle — if you cannot explain why a rule exists in principled terms, the rule is probably wrong. SOPs must be derivable from policy — if a procedure conflicts with its parent policy, the procedure must change.
This hierarchy is not just theoretical tidiness. When a regulator or a court evaluates your program, they trace the chain: is this procedure consistent with that policy? Is that policy consistent with a stated principle? Gaps in the chain — places where no policy covers a situation, or where a policy contradicts another — are finding magnets.
The practical implication: policy owners must know both layers above and below them. A policy that is logically consistent with principle but operationally impossible to implement produces SOPs that quietly deviate — and quiet deviation is how scandals begin.
03Code of Conduct as instrument — how Pfizer, J&J, and MSD approach it
The Code of Conduct sits at the top of the policy stack, closest to principle. In most large pharma companies it is also the document most employees actually encounter — often annually, via mandatory training and certification.
What makes a Code of Conduct effective as an instrument rather than a formality? Three features stand out when you compare the public versions that major companies publish.
Coverage without exhaustiveness
Pfizer's Code covers a wide range of situations — scientific integrity, promotion, anti-corruption, privacy, conflicts of interest — but does so in relatively plain language, deferring detail to supporting policies. J&J's equivalent emphasizes the four-credo hierarchy (patients, employees, communities, shareholders in that order) as an explicit decision framework, not just a values statement. MSD's Code (MSD is the trade name used outside North America for what is sold as Merck in the United States and Canada) is notable for its scenario-based structure: many sections include "how this applies in practice" vignettes — short worked examples — that help employees connect an abstract rule to a concrete situation.
The common thread: a Code that tries to be complete fails. One that provides a framework for thinking — and points to where to find more specific rules — succeeds.
Accountability architecture
Codes that work include a clear accountability structure: who sets the policy, who enforces it, who employees can go to when they are uncertain. This is not bureaucratic decoration. An employee who does not know who owns a rule will not follow it consistently.
Explicit scope for third parties
Modern Codes explicitly extend their obligations to contractors, distributors, and agents — the supply chain and commercial partners through whom a violation is just as likely to originate as from an internal employee. This has been a focus of DOJ enforcement guidance since at least 2012.
04Conflict of Interest policy — Sunshine, transparency, and KOL transactions
No policy area in pharma generates more day-to-day friction than conflict of interest (a conflict of interest, sometimes shortened to COI, is any situation where a personal interest could distort a professional judgment). The reason is structural: pharma's business model requires genuine scientific partnerships with the physicians who prescribe its products — including KOLs (key opinion leaders, the influential expert physicians a field looks to). Those partnerships — speaker programs, advisory boards, research collaborations, educational grants — are also the primary vectors through which improper influence can flow.
The Sunshine Act and its descendants
In the United States, the Physician Payments Sunshine Act (enacted as part of the Affordable Care Act in 2010) requires drug and device manufacturers to report annually to the Centers for Medicare & Medicaid Services (CMS, the U.S. government agency that runs public health insurance) any payment or transfer of value to covered recipients (physicians, teaching hospitals, certain advanced practice practitioners). The data is published in the Open Payments database, freely searchable by anyone.
The Sunshine Act did not make these payments illegal. It made them visible. Visibility, the theory goes, allows physicians, patients, and institutions to evaluate whether a relationship has colored a clinical recommendation. The empirical evidence on whether disclosure changes behavior is mixed — but disclosure has become a baseline expectation internationally, with analogous transparency schemes in the EU (the EFPIA Disclosure Code — EFPIA is the European pharma industry federation), the UK (the ABPI, the British pharma industry association), Australia, and Japan.
Japan's framework: the JPMA Transparency Guidelines
In Japan, the Japan Pharmaceutical Manufacturers Association (JPMA — the major industry body, whose Japanese name is 日本製薬工業協会) publishes Transparency Guidelines that member companies follow. Unlike the U.S. Sunshine Act, Japan's system is self-regulatory rather than statutory: companies disclose transfers of value to healthcare professionals and institutions on their own websites, in a standardized format, annually. The disclosed categories include research fees, consulting fees, speaker honoraria, manuscript fees, and expenses (travel, accommodation, meals).
The absence of a statutory mandate does not make the obligation less real. JPMA membership carries reputational weight, and deviation from the Guidelines is visible to regulators, institutional procurement committees, and media. In practice, Japan subsidiaries of global companies operate under both the JPMA Guidelines and their parent company's global disclosure policy — and the more stringent of the two governs.
What a Conflict of Interest policy must do
- Define "conflict" broadly enough to catch financial, relational, and positional conflicts — not just obvious cash payments
- Require disclosure to a designated function (Compliance, Legal, or a committee) before the relationship proceeds
- Specify decision authority — who can approve, who must escalate, what categories are pre-approved
- Require documentation of the fair market value basis for any payment, and the legitimate business purpose for any interaction
- Apply to procurement, not only commercial activity — a purchasing manager who sources from a vendor in which she has a personal financial stake has a conflict of interest just as surely as a sales representative does
05Anti-bribery and anti-corruption — four frameworks, one standard
Bribery in pharma takes many forms: a payment to a government procurement official to put a drug on the national formulary, a "consulting" arrangement with a hospital administrator who controls which drugs get stocked, a travel sponsorship for a physician that is really a reward for past prescribing. The legal frameworks that address this are international, overlapping, and — for global companies — all simultaneously applicable.
FCPA — the U.S. Foreign Corrupt Practices Act
Enacted in 1977 and a major enforcement priority since the mid-2000s, the FCPA prohibits U.S. persons and companies, and foreign companies listed on U.S. exchanges, from paying bribes to foreign government officials to obtain or retain business. "Government official" in the pharma context includes physicians employed at state hospitals. That category covers most hospital doctors in many countries, including China and much of Europe — so an ordinary gift to a hospital physician abroad can fall under the law. FCPA enforcement against pharma companies (Novartis, Teva, Pfizer and other major pharma companies have faced investigations) has made the law familiar across the industry globally.
UK Bribery Act
The UK Bribery Act 2010 goes further in two ways. First, it covers commercial bribery — paying a private-sector employee to do something favorable — not only bribes of government officials. Second, it creates a strict-liability offense for failing to prevent bribery: a company is guilty if a person "associated" with it (which includes third-party agents and distributors) pays a bribe on its behalf, unless the company can demonstrate it had "adequate procedures" in place. "Adequate procedures" has become a term of art (= a phrase with a fixed, specialized legal meaning): the UK Ministry of Justice has published six principles (proportionate procedures, top-level commitment, risk assessment, due diligence, communication, monitoring and review) against which a program is evaluated.
Japan — Unfair Competition Prevention Act
Japan addresses bribery of foreign officials through the Unfair Competition Prevention Act (不正競争防止法, Fusei Kyoso Boshi Ho), which was amended in 1998 to comply with the OECD Anti-Bribery Convention (the OECD is the Organisation for Economic Co-operation and Development, a group of mostly wealthy democracies that sets shared policy standards). It prohibits payments to foreign public officials in connection with international transactions. Domestically, a separate framework — the Act against Unjustifiable Premiums and Misleading Representations and various medical institution procurement rules — governs relationships with Japanese healthcare professionals and public hospitals.
JPMA Code — transfer-of-value provisions
The JPMA Code of Practice (自主規範) includes specific provisions on what member companies may and may not offer to healthcare professionals: limits on meal expenses, prohibitions on entertainment unconnected to a genuine scientific purpose, requirements that speaker fees be calibrated to FMV. These provisions overlap with the Transparency Guidelines and are enforced via the JPMA's self-governance mechanism — companies that violate the Code may be subject to JPMA review and, in serious cases, public disclosure of findings.
For a Japan subsidiary of a global pharma company, all four frameworks are simultaneously operative. A global anti-bribery policy must satisfy the most stringent applicable standard — which in practice usually means UK Bribery Act "adequate procedures" as the design benchmark, with FCPA enforcement history as the risk-calibration guide.
06Data Integrity policy — ALCOA+, GxP, and research honesty
If anti-bribery policy protects the boundary between the company and external parties, data integrity policy protects the boundary between what the company knows and what it says it knows. That boundary — between internal data and reported data — is where regulatory systems place enormous trust. When it breaks, the consequences are severe: warning letters, import alerts, consent decrees, and in serious cases, criminal prosecution.
ALCOA+ as the organizing framework
The FDA (the U.S. Food and Drug Administration, the American drug regulator) and the EMA (the European Medicines Agency, the EU's drug regulator) both use the ALCOA+ acronym to describe the properties of reliable data in GxP-regulated environments (GxP is shorthand for the family of official "Good Practice" standards that protect medicine quality — the x stands in for Manufacturing, Clinical, Laboratory, and so on):
- Attributable — it is clear who recorded the data and when
- Legible — it can be read now and in the future
- Contemporaneous — it was recorded at the time of the activity, not reconstructed later
- Original — it is the first capture or a certified copy
- Accurate — it correctly reflects what was observed or measured
The "+" extends these with Complete, Consistent, Enduring, and Available. These eight properties define what regulators expect data to be. A data integrity policy translates them into organizational requirements: who may amend a record (and how), how audit trails are protected, what happens when a discrepancy is found, and how raw data is retained.
GxP integration
Data integrity requirements apply across all GxP domains — Good Manufacturing Practice (GMP), Good Clinical Practice (GCP), and Good Laboratory Practice (GLP) — though their specific expression differs. In GMP, the focus is on batch records, equipment logs, and environmental monitoring data. In GCP, it is source data at clinical sites, electronic data capture systems, and audit trails in clinical trial management systems. In GLP, it is laboratory notebooks and instrument raw data.
A policy that treats these as separate problems misses the shared risk: in each domain, the temptation is the same — to fix a data point that makes a product look bad, or to reconstruct a record that was not made contemporaneously. A unified data integrity policy states the organization's position on this temptation and the consequences of yielding to it.
Research integrity — beyond GxP
Data integrity in the regulatory-submission sense is well-covered in most pharma Quality Management Systems. Less uniformly covered is research integrity in the broader sense: ghost-writing of publications, selective reporting of clinical data, post-hoc endpoint changes in sponsored trials. These are not always GxP violations — they occur in contexts (medical communications, investigator-sponsored studies) where GxP does not formally apply. But they carry equal or greater reputational risk and have attracted increasing attention from medical journals, academic institutions, and regulators in Europe and the United States.
A complete data integrity policy extends its principles into these contexts explicitly.
07What "implementation" actually means
Writing a policy is the easy part. The gap between a written policy and actual behavior is where most compliance programs fail. Implementation has three components: training, monitoring, and response to violation.
Training
Annual mandatory training is the baseline. It is also, by itself, insufficient. Research on compliance training consistently finds that knowledge gained in a one-hour module decays rapidly and does not reliably change behavior in ambiguous situations — which are the situations that matter.
Effective training supplements the annual module with role-specific, scenario-based learning delivered closer to the moment of need. A newly hired medical affairs manager learns the conflict-of-interest policy not only in new-hire orientation but in a workshop that simulates real advisory board scenarios. A sales manager encounters the anti-bribery policy not only in an e-learning module but in coaching from a compliance business partner before a KOL event.
"Training is not what happens in the classroom. Training is what changes what people do at their desks on Tuesday morning." — a formulation sometimes attributed to behavioral compliance researchers working with DOJ.
Monitoring
Policies require monitoring to be real. Monitoring can be transactional (reviewing every expense report above a threshold, auditing a sample of KOL contracts) or systemic (analyzing payment data for patterns that suggest off-policy behavior, comparing disclosed ToV with contracting records).
The trend in pharma compliance is toward data analytics: using internal data (CRM records, payment databases, travel and expense systems) to identify anomalies that warrant follow-up. This is more scalable than manual review and, when done well, more protective — it catches patterns that individual reviewers miss.
Response to violation
How an organization responds to a policy violation signals, more than any training program, what the organization actually values. The key dimensions:
- Consistency — applying the same consequence to the same violation regardless of the seniority of the person involved
- Speed — investigating promptly; allowing situations to drift while under investigation creates additional harm
- Root-cause orientation — treating a violation as information about system failure, not only individual failure
- Transparency — communicating outcomes (appropriately de-identified) so that others understand what the policy means in practice
08Particular challenges of Japan subsidiaries
For employees at Japan subsidiaries of global pharma companies — which describes most of the industry in Japan — policy implementation carries a specific set of challenges that deserve separate attention.
Global-parent policy translation
Global policies are written primarily in English and calibrated to the most stringent globally applicable regulatory environment. When translated into Japanese and applied to the Japan business, they encounter three friction points.
Legal framework differences: Japan's regulatory structure for HCP interactions is largely self-regulatory (JPMA Code, company SOPs) rather than statutory (as in the U.S. Sunshine Act). This means compliance requirements are often set internally by the Japan affiliate in dialogue with the parent — and the parent's global policy may be more restrictive than local law requires, or may use concepts (like "government official") that have different scope in Japan than in the U.S.
Cultural context: Japanese business culture places high value on relationship maintenance (関係性, kankesei) and gift-giving as expressions of professional respect. Global anti-bribery and ToV policies that categorically restrict meals and gifts can collide with local professional norms in ways that generate compliance resistance — not because employees are trying to behave corruptly, but because they are trying to navigate a cultural expectation that the global policy does not acknowledge.
Translation ambiguity: Compliance concepts that are clear in English — "transfer of value," "associated person," "adequate procedures" — often lack direct Japanese equivalents. The translation process can introduce ambiguity, or resolve it in ways that the policy authors did not intend. Japan subsidiaries that simply translate the global policy without adaptation often end up with documents that employees cannot use.
Local accountability structures
In global companies, Compliance functions at the Japan subsidiary level typically report to both a local executive and a global compliance leader. This dual reporting line can create tensions when global standards and local business pressures diverge. The Japan Compliance Officer's ability to escalate issues upward — and to be genuinely heard — is a significant factor in whether the policy framework functions or is quietly worked around.
09Three remaining challenges
Even well-designed policy frameworks face structural challenges that have not been fully solved.
Policy proliferation and navigability
Large pharma companies often have dozens of policies, hundreds of SOPs, and layers of guidance documents. Employees facing a real decision in real time frequently cannot navigate this corpus. An employee who cannot find the applicable policy in three minutes will not use it. Policy architecture — how policies are organized, how they reference each other, how they are surfaced at the moment of need — matters as much as policy content.
Third-party reach
The most significant compliance risks in modern pharma increasingly reside outside the direct workforce — in contract research organizations, distributors, co-promotion partners, and patient services vendors. Policies bind employees; they do not automatically bind third parties. Extending policy reach to third parties requires due diligence, contractual obligations, and monitoring — all of which add cost and complexity that organizations tend to underinvest in until after a problem occurs.
The speed of emerging risks
Digital health, AI-assisted clinical decision tools, patient influencer relationships, social media promotional content — these areas are generating compliance questions faster than policy cycles can address them. A policy updated every two years has limited utility in a domain where the risk landscape shifts every six months. Organizations are experimenting with faster-cycle guidance documents and compliance advisory functions that can respond in near-real time — but the tension between the stability that policy requires and the speed that emerging risks demand remains unresolved.
10Connections to other chapters
Policy is not a standalone topic. Its meaning depends on the system it sits inside.
- Compliance 01 — The five walls between pharma and patients (information, institution, economics, time, psychology) explain why these policies exist. Each policy in this chapter addresses at least one of those walls: data integrity addresses the information wall; anti-bribery addresses the economic wall; conflict of interest addresses all five simultaneously
- Compliance 02 — Social trust is what policies are protecting at the industry level. A violation of the anti-bribery policy by one company degrades the trust reservoir that the entire industry draws on
- Compliance 03 (Whistleblowing) — The response-to-violation component of implementation depends on a functioning speak-up mechanism. Employees who observe policy violations must have a credible channel to report them; without that channel, monitoring and response are both crippled
- Ad Regulations — Promotional compliance and Code of Conduct provisions on promotion are closely linked. The boundary between legitimate medical education and off-label promotion is a policy question before it is a legal question
- Material Review — The material review function is, among other things, a policy-implementation mechanism: it operationalizes the Code of Conduct's requirements on promotion, data integrity, and fair balance at the level of individual pieces of content
Policies are the document layer between what an organization believes and what it does. That sentence sounds modest. In practice, it describes something that takes sustained organizational effort to maintain: clear text, consistent training, active monitoring, credible response to violation, and the humility to update when the policy is not working.
The companies that handle policy well are not those with the most pages of documentation. They are those where an employee facing a real ethical decision on a Tuesday morning knows where to look, trusts that the answer is there, and believes that following it will be respected — not worked around by the people above her.
That is the gap this chapter is trying to name. Not between what the policy says and what regulators require. Between what the policy says and what actually happens. Closing that gap is the daily work of compliance.