Annual code of conduct attestation requirements
No US federal statute sets a 365-day code of conduct clock for all employees, yet almost every company runs one. Here is what the SEC, NYSE, Nasdaq and DOJ actually require, how attestation differs from training, and what a record has to contain to survive a review.
By the CompanyLMS team
August 2026 · 8 min read
Last updated August 2026.
An annual code of conduct attestation is a dated, signed record that an employee has read the current code, understands it, and agrees to comply. No US federal statute sets a fixed 365-day clock for all employees. The annual cadence comes from the Department of Justice expecting "periodic" training and certification, from NYSE and Nasdaq listing standards requiring a published code, and from auditors and insurers who treat a yearly cycle as the reasonable reading of "periodic."
That distinction matters more than it sounds. Companies that assume a law mandates annual attestation tend to run the exercise as a box-tick, and companies that assume nothing is required tend to skip it until an investigator asks for records. Both end up in the same place, which is unable to produce a dated record for a specific person on a specific version of the code.
What is a code of conduct attestation?
It is the acknowledgment step at the end of the process, and it is a separate artifact from the training. Training is the course that explains conflicts of interest, gifts and entertainment, insider trading, anti-bribery rules and how to report concerns. Attestation is the employee affirming, in a record you can retrieve later, that they received the code, read it, and will follow it.
Most programs bundle a second element into the same form: a disclosure. The employee is asked whether they are aware of any violation, and whether they have any relationship or outside interest that could create a conflict. That disclosure is often the more valuable half. It surfaces the side consultancy, the supplier run by a relative, and the board seat nobody mentioned, and it does so on a dated record that shows the company asked.
Is annual code of conduct training required by law?
Not as a general federal mandate with a fixed interval. What exists is a set of overlapping requirements that push strongly toward an annual cycle without any of them writing the word "annually" for all staff. Here is what each source actually says.
| Source | What it actually requires | Who it covers | Interval it sets |
|---|---|---|---|
| SOX Section 406 and Item 406 of Regulation S-K | Disclose whether you have adopted a code of ethics, and disclose amendments and waivers | Public companies. CEO, CFO, controller, principal accounting officer or equivalent | None. It is a disclosure rule, not a training schedule |
| NYSE Listed Company Manual 303A.10 | Adopt and disclose a code of business conduct and ethics, and promptly disclose waivers for directors and executive officers | NYSE-listed companies. All directors, officers and employees | None specified |
| Nasdaq Listing Rule 5610 | Adopt and publicly disclose a code of conduct meeting the SOX 406(c) definition, and disclose waivers | Nasdaq-listed companies. All directors, officers and employees | None specified |
| DOJ Evaluation of Corporate Compliance Programs | Prosecutors assess whether policies are integrated through periodic training and certification | Directors, officers, relevant employees, and where appropriate agents and business partners | "Periodic." Annual is the practice that grew up around it, not the text |
| US Sentencing Guidelines 8B2.1 | Periodic, practical communication of standards and procedures to all levels of the organization | Any organization seeking credit for an effective program at sentencing | "Periodically" |
| Private, non-listed companies | Nothing federally. Requirements arrive through contracts, customers, investors and insurers | Whoever the contract names | Set by whoever is asking, commonly annual |
Read that table and the practical answer becomes clear. The listing standards require you to have a code and publish it. The DOJ guidance is the one that reaches training and certification, and it uses the word "periodic." Nobody writes "every 365 days." Annual won because it matches the fiscal year, satisfies a reasonable reading of "periodic," and gives auditors a clean population to sample.
If you are a private company with no listing and no federal contracts, you are not breaking a law by skipping this. You may still be breaking a customer contract, an investor covenant or a condition of your directors and officers insurance, which is where most private companies actually meet the requirement.
Attestation and training are different records, and auditors ask for the attestation
This is the practical failure mode. A company runs a good annual ethics course, tracks completions carefully, and then cannot answer the only question that gets asked: show me that this named person acknowledged this version of the code on this date.
Course completion says somebody watched the material. Attestation says they accepted an obligation. In an investigation, a wrongful termination claim, or a due diligence review, the second one is the document that does work. If your employee handbook says a policy violation is grounds for dismissal, the attestation is what establishes the person was on notice of the policy.
Keep both, and keep them linked. The defensible package is the course completion, the attestation, and the exact version of the code that was in force, all pointing at the same person and date.
What a defensible attestation record contains
Six fields separate a record that holds up from a spreadsheet row that does not.
- The exact version of the code attested to. A version number or effective date, not a link to whatever is on the intranet today. If the code changed in March, a February attestation covers the old text and you need to know that.
- A real timestamp. Date and time captured by the system, not typed into a cell by an administrator afterwards.
- Identity you can defend. Attestation through single sign-on or a unique authenticated login. A shared link that anyone in the company could click proves very little.
- The affirmative statements, in full. Received, read, understood, agrees to comply, and will report known violations. Store the wording that was shown, because it will change over the years.
- The disclosure response. Whether the person disclosed a conflict or a known violation, what they said, and where it was routed. An unrouted disclosure is worse than no disclosure.
- Retention that outlives employment. The record needs to be retrievable after the person leaves, and after the administrator who ran the cycle leaves.
That last point is where spreadsheets and shared drives quietly fail. The file survives; the context does not. Two years later nobody can say which version of the code the March tab referred to, and the person who would have known has moved on.
How often should employees re-attest?
Annual is the sensible default, but the calendar is only one of five triggers. A program that only runs once a year has gaps a reviewer will find.
- At hire. Common practice is within the first 30 days, as part of onboarding, before the person has meaningful access to systems or customers.
- Annually. Usually tied to the fiscal year so the population matches the audit period.
- After a material revision. If you rewrite the gifts and entertainment section, last year's attestation does not cover it. Re-attest the affected population rather than waiting for the next cycle.
- On promotion or role change. Moving into a role that handles purchasing, financial reporting or government contact usually triggers a supplemental attestation with a narrower disclosure form.
- At contract renewal for third parties. Covered in the next section.
Whatever cadence you pick, write it down in the program document and follow it. A reviewer comparing your stated policy against your actual records is looking for the gap between them, not for a particular interval. Missing your own annual deadline by four months is worse than having chosen an eighteen-month cycle deliberately.
Do you need code of conduct attestations from suppliers and third parties?
If you are exposed to federal enforcement, plan for it. The DOJ guidance explicitly reaches agents and business partners where appropriate, and asks whether companies obtain updated due diligence, training and annual compliance certifications from third parties. Anti-bribery risk is the usual driver, since a distributor or agent acting on your behalf in a foreign market can create liability you did not sign off on.
In practice this means a supplier code of conduct attestation collected at onboarding and refreshed at contract renewal, weighted by risk rather than applied uniformly. A stationery supplier does not need the same treatment as a sales agent operating in a high-risk jurisdiction. Tiering by risk is defensible; treating every vendor identically is expensive and, if you cannot keep up with it, less defensible than a smaller program you actually complete.
The mechanics are the same as the internal cycle: send the current code, capture a dated acknowledgment from a named signatory, and store it where you can retrieve it during due diligence. For third parties who sit outside your systems and will never have a login, a straightforward way to send a document out for signature and get a dated, verified copy back is usually simpler than trying to provision external accounts on your training platform.
How to run the annual attestation cycle without a spreadsheet
The work is not the attestation itself, which takes an employee four minutes. The work is the chase, the reconciliation and the evidence pack, and that scales badly by hand. A cycle covering 800 people typically means several hundred non-responses in week one, a headcount list that was already stale when you exported it, and a manual reconciliation against HR data at the end.
Four things make it manageable at any size.
- Start from live HR data, not an export. If new joiners and leavers sync automatically, the population is correct on the day you report rather than on the day you exported.
- Automate the reminders. Escalating nudges to the employee, then to the manager, remove almost all of the chase. Manager visibility of their own team's completion is the single most effective lever.
- Version the content. Assign a specific version of the code so every record points at known text.
- Make the evidence pack a report, not a project. You should be able to produce, on demand, a dated per-person list showing who attested, to which version, and who did not.
That is ordinary certification tracking applied to a policy rather than a credential, which is why most companies run it on the same platform that handles the rest of their mandatory training. If you are evaluating options, the best compliance training software roundup compares the platforms on tracking and audit proof, and the compliance training software pricing breakdown covers what the category actually costs per employee, including the difference between buying a course library and buying the platform that proves people completed it.
For the tracking mechanics specifically, certification tracking software covers expiry alerts and dated records, and how to track employee certifications works through the process end to end. If you are still deciding what belongs in the program at all, compliance training topics lists what US employers typically cover.
Common questions
What is the difference between an attestation and a certification?
In compliance usage they are close to interchangeable, and the DOJ guidance uses "certification." Attestation tends to describe the employee affirming they read and will follow a policy. Certification more often describes a periodic statement of ongoing compliance, sometimes from a manager or officer about their area rather than about themselves. Pick one term, define it in your program document, and use it consistently.
Does an electronic acknowledgment hold up?
Yes, provided you can show who acknowledged, when, and to what. Under the federal E-SIGN Act an electronic signature is not denied legal effect simply for being electronic. The weakness in practice is almost never the signature technology; it is a record that cannot prove which version of the document the person actually saw.
How long should we keep attestation records?
Longer than you expect to need them, and longer than the employment. Employment claims can arrive years after a departure, and due diligence in an acquisition routinely reaches back several years. Many programs align retention with their broader employment record schedule. Check the default on any system you buy, because vendors commonly default to around two years, which is short for this purpose.
What if an employee refuses to sign?
Record the refusal with the same care as an acknowledgment, including the date and any stated reason, and route it to HR and legal rather than leaving it as a blank row. A documented refusal is a manageable event. A missing record that later turns out to have been a refusal is the problem, because it looks identical to an administrative failure.
See CompanyLMS train your teams
Build courses, launch employee onboarding and compliance training, track skills across teams, and issue certifications, all in one corporate LMS, with completion visible on a single progress dashboard.