Unit 5: Corporate Ethics and Governance

MGN253 — Human Values And Business Ethics 10 min read

I. Ethical Foundations of Corporate Conduct

Corporate ethics applies moral principles to organizational decisions, conduct, relationships, and impacts. It requires a corporation to pursue legitimate economic objectives while respecting law, stakeholder rights, human dignity, fairness, and environmental sustainability. Governance supplies the structures through which these responsibilities are directed, monitored, and enforced.

  • Core principle—responsible value creation: A business should create durable economic value without imposing unjustified harm or transferring hidden costs to employees, consumers, communities, or future generations.
  • Moral agency: Although a corporation is an artificial legal person, ethical decisions are made by directors, executives, managers, and employees acting individually and collectively.
  • Stakeholder orientation: Relevant stakeholders include shareholders, employees, customers, suppliers, creditors, regulators, local communities, and the natural environment.
  • Ethical decision standard: A defensible decision should satisfy several tests:
    • Legality: Does it comply with applicable law?
    • Rights: Does it respect privacy, safety, equality, and informed choice?
    • Fairness: Are benefits, risks, and burdens distributed justly?
    • Consequences: What foreseeable short- and long-term effects will result?
    • Transparency: Could the reasons for the decision be disclosed publicly?
  • Integrity infrastructure: Ethical conduct depends on board oversight, leadership example, codes of conduct, training, reporting channels, incentives, audits, and consistent discipline.
  • Accountability: Responsibility requires identifiable decision-makers, reliable records, independent review, corrective action, and remedies for affected persons.

II. Law and Ethics — Minimum Rules and Higher Responsibilities

A. Law versus ethics

Law and ethics overlap, but law establishes enforceable minimum standards whereas ethics asks what conduct is right, fair, and responsible.

  1. Law

    • Source: Law arises from constitutions, legislation, regulations, judicial decisions, and legally binding contracts.
    • Enforcement: Courts and regulators may impose fines, damages, licence cancellation, injunctions, or imprisonment.
    • Precision and jurisdiction: Legal duties are formally defined and may differ across countries; data processing lawful in one jurisdiction may be restricted in another.
    • Compliance question: Legal analysis asks, “What must or must not the organization do?”
  2. Ethics

    • Source: Ethics draws on values, professional duties, human rights, social expectations, and principles such as honesty, justice, non-maleficence, and respect.
    • Enforcement: Consequences include loss of trust, employee disengagement, consumer boycotts, investor action, or reputational damage even where no offence exists.
    • Broader scope: Ethical responsibility covers conduct not yet regulated, such as deploying a novel algorithm before specific legislation applies.
    • Moral question: Ethical analysis asks, “What ought the organization to do?”
  • Overlap: Fraud, bribery, discrimination, and unsafe products are generally both unlawful and unethical because they violate enforceable rules and basic moral duties.
  • Legal but unethical conduct: Aggressive tax avoidance, deliberately confusing contract terms, or exploiting weak labour laws may satisfy technical rules while violating fairness and good faith.
  • Ethical but legally restricted conduct: Whistleblowing or civil disobedience may be morally justified in exceptional circumstances but still breach confidentiality or other legal rules.
  • Changing relationship: Ethical expectations often precede legislation; public concern about privacy, pollution, or workplace safety can later produce binding regulation.

B. Ethical Decision-Making Beyond Compliance

Compliance should be the starting point, not the final measure, of corporate responsibility.

  • Structured test: Managers can document a decision through the following sequence:
    1. Identify facts, stakeholders, applicable laws, and conflicts of interest.
    2. Generate alternatives rather than treating the proposed action as inevitable.
    3. assess rights, fairness, consequences, reversibility, and public defensibility.
    4. Approve, record, monitor, and revise the decision if harm appears.
  • Publicity test: A decision requiring secrecy because informed stakeholders would reject it signals ethical weakness, even if disclosure is not legally required.
  • Limitation of rules: “Creative compliance” can defeat a law’s purpose while observing its wording; ethics therefore examines substance over form.
  • Concrete example: If a lawful advertising campaign targets financially vulnerable users with high-cost credit, an ethical review should consider informed consent, exploitative design, repayment harm, and safer targeting—not legality alone.

III. Organizational Values and Ethics — From Principles to Culture

A. Values and ethics in organizational context

Organizational values are declared priorities, while organizational ethics concerns how those priorities govern actual choices, systems, and behaviour.

  • Values: Integrity, respect, responsibility, excellence, fairness, and sustainability express what an organization considers important.
  • Ethics: Ethics converts broad values into standards—for example, “integrity” becomes accurate reporting, truthful marketing, and prohibition of bribery.
  • Code of ethics: A principles-based code explains expected judgment; a code of conduct states operational rules concerning gifts, harassment, confidentiality, conflicts, and company assets.
  • Ethical culture: Culture is reflected in “how work is really done,” especially when targets conflict with stated values.
  • Tone at the top: Directors and senior executives establish credibility by disclosing conflicts, accepting scrutiny, and refusing profitable misconduct.
  • Tone in the middle: Supervisors translate policy into daily decisions about workloads, sales methods, evaluations, and retaliation; their behaviour often affects employees more directly than executive statements.
  • Incentive alignment: Rewarding only quarterly sales can encourage mis-selling. Balanced evaluation may include customer complaints, product quality, employee safety, and compliance.
  • Psychological safety: Employees must be able to question decisions and report concerns without retaliation.

B. Institutionalization and Assessment

Values become effective only when embedded in governance, human-resource, operational, and assurance systems.

  • Ethics programme: Core elements include induction training, periodic scenario-based learning, confidential advice, whistleblowing channels, investigation protocols, and proportionate discipline.
  • Conflict-of-interest control: Employees should disclose financial interests, family relationships, gifts, or outside roles that could impair objective judgment.
  • Speak-up mechanism: Anonymous hotlines and direct access to an audit or ethics committee help bypass compromised management channels.
  • Measurement: Indicators include substantiated complaints, retaliation allegations, training completion, investigation time, staff survey results, supplier breaches, and repeat violations.
  • Consistency test: Discipline should depend on the misconduct rather than the offender’s rank or revenue contribution.
  • Limitation: A values statement becomes “ethics washing” when public commitments are not supported by budgets, incentives, evidence, or consequences.

IV. Corporate Governance — Direction, Oversight, and Accountability

A. Corporate governance and ethical practices

Corporate governance is the system by which companies are directed, controlled, and held accountable, including relationships among the board, management, shareholders, and other stakeholders.

  • Board of directors: The board approves strategy, selects and supervises senior management, oversees risk, and protects the company’s long-term interests.
  • Fiduciary responsibilities: Directors are generally expected to exercise care, loyalty, good faith, informed judgment, and proper-purpose decision-making.
  • Independence: Independent directors can challenge management, review related-party transactions, and reduce domination by executives or controlling shareholders.
  • Board committees:
    • Audit committee: Oversees financial reporting, internal control, external audit, and whistleblowing arrangements.
    • Nomination committee: Supports competent, diverse, and transparent board appointments.
    • Remuneration committee: Aligns executive rewards with sustainable performance and appropriate risk.
    • Risk or sustainability committee: Oversees material operational, environmental, social, cyber, and reputational risks.
  • Transparency: Accurate, timely disclosure reduces information asymmetry between management and investors.
  • Ethical practices: Anti-bribery controls, fair procurement, related-party disclosure, responsible lobbying, tax integrity, and protection of minority shareholders strengthen legitimacy.

B. Governance Failures and Safeguards

Governance mechanisms address agency problems but cannot replace independent judgment and ethical leadership.

  • Agency problem: Managers may pursue bonuses, status, or short-term growth rather than the organization’s long-term interests.
  • Control safeguards: Segregation of duties, authorization limits, internal audit, external audit, board evaluation, and risk reporting reduce opportunities for abuse.
  • Three-lines model:
    1. Operating management owns and manages risk.
    2. Risk and compliance functions provide oversight and guidance.
    3. Internal audit independently evaluates controls.
  • Red flags: Dominant chief executives, complex transactions, suppressed bad news, frequent auditor changes, unrealistic targets, and retaliation against critics indicate elevated governance risk.
  • Limitation: Formal independence does not guarantee real independence; directors may remain passive because of social ties, weak expertise, or inadequate information.

V. ESG — Sustainability, Stakeholders, and Enterprise Risk

A. Environmental, Social and Governance (ESG)

Environmental, Social and Governance criteria organize information about a company’s sustainability impacts, dependencies, risks, opportunities, and oversight.

  • Environmental: Covers greenhouse-gas emissions, energy, water, pollution, biodiversity, waste, resource efficiency, and climate adaptation.
    • Emissions scopes: Scope 1 covers direct emissions; Scope 2 covers purchased energy; Scope 3 covers other value-chain emissions.
  • Social: Covers labour standards, health and safety, diversity, human rights, product responsibility, customer welfare, and community effects.
  • Governance: Covers board structure, executive pay, audit quality, business ethics, tax practices, political activity, cybersecurity, and shareholder rights.
  • Materiality: An ESG issue is financially material when it could affect enterprise value; impact materiality concerns significant effects on people or the environment.
  • Reporting frameworks: GRI emphasizes organizational impacts, while IFRS S1 and IFRS S2 focus on sustainability-related and climate-related financial disclosures for investors.
  • Strategic value: ESG analysis can reveal supply-chain disruption, stranded assets, regulatory exposure, employee turnover, or opportunities in low-carbon products.

B. Measurement and Integrity

Credible ESG practice requires measurable targets, governance oversight, comparable data, and assurance.

  • Metric design: A target should specify baseline, indicator, boundary, deadline, and accountable owner.
TEXT
Emissions intensity = Total greenhouse-gas emissions / Unit of output
  • Definitions: Emissions are commonly expressed as tonnes of carbon-dioxide equivalent; output may be revenue, products manufactured, or energy generated.
  • Due diligence: Companies should identify, prevent, mitigate, track, and communicate significant environmental and human-rights impacts across operations and supply chains.
  • Greenwashing risk: Selective disclosure, vague claims such as “eco-friendly,” hidden trade-offs, and unsupported net-zero pledges mislead stakeholders.
  • Safeguards: Consistent boundaries, disclosed methodologies, board review, external assurance, and reporting of negative as well as positive results improve reliability.
  • Limitation: ESG ratings may diverge because agencies use different data, weights, materiality judgments, and scoring methods.

VI. Digital Responsibility — Data, Algorithms, and Human Oversight

A. Digital ethics and responsible use of AI

Digital ethics applies rights, fairness, accountability, safety, and human-centred values to data, platforms, automated systems, and artificial intelligence.

  • Privacy: Organizations should collect data for legitimate, specified purposes and apply data minimization, access controls, retention limits, and secure deletion.
  • Informed choice: Consent should be understandable and freely given rather than obtained through manipulative “dark patterns.”
  • Fairness: AI systems should be tested for unjustified differences across relevant groups; biased historical hiring data can reproduce past discrimination.
  • Transparency: Users should know when they interact with AI and receive meaningful information about consequential automated decisions.
  • Explainability: The required explanation depends on context; a medical or credit decision requires greater interpretability than a low-risk recommendation.
  • Accountability: A named human or committee must remain responsible for approval, monitoring, incident response, and remedies.
  • Safety and security: Testing should address inaccurate outputs, adversarial attacks, data leakage, harmful content, automation bias, and model drift.
  • Human oversight: High-impact decisions should permit competent review, intervention, appeal, and reversal rather than ceremonial human approval.

B. Responsible AI Governance and Limitations

Responsible AI governance controls the complete system lifecycle rather than evaluating only the final model.

  • Lifecycle controls: Define the purpose, assess necessity, document data provenance, test performance, authorize deployment, monitor outcomes, and retire unsafe systems.
  • Risk classification: Greater potential harm requires stronger controls; biometric identification, employment screening, credit assessment, healthcare, and critical infrastructure demand heightened scrutiny.
  • Documentation: Model cards, data records, validation reports, decision logs, and incident registers support traceability and audit.
  • Impact assessment: Evaluation should cover affected groups, error severity, misuse, environmental cost, accessibility, and available remedies.
  • Vendor governance: Contracts should specify security, permitted data use, intellectual-property responsibilities, audit access, service continuity, and incident notification.
  • Generative-AI controls: Users should verify outputs, protect confidential information, disclose synthetic content where material, and avoid treating generated text as authoritative evidence.
  • Limitations: Bias cannot be solved by accuracy alone, explanations may oversimplify complex models, and human reviewers can become over-reliant on automated recommendations.
  • Practical standard: AI should not be deployed merely because it is technically possible; use must be necessary, proportionate, contestable, and consistent with organizational values.