Skip to content

Conflict Management Plan

Composite control plan — instantiates Conflict-of-Interest Mitigation

Assembles a matter-specific bundle of proportionate controls — with owners, evidence, and an expiry — when no single measure covers all the influence paths but full disqualification is unnecessary.

Version
v1 · 2026-08-24 · History
Mechanism #
1752
Type
Composite Control Plan
Form family
Representation, Specification & Plan
Solution family
Governance & Accountability
Problem family
Incentive Conflict, Gaming & Collective-Action Failure
Problem subfamily
Delegated Interest Conflict & Capture
Origin domain
Law & Governance
Also from
Accounting & Auditing, Medicine & Healthcare
Instantiates
Conflict-of-Interest Mitigation

Real conflicts rarely have one clean influence path, and the strongest remedy is not always available or wise. Conflict Management Plan is the artifact that handles the in-between case: it selects and packages several controls — some disclosure here, a firewall there, supervision on one task, recusal from another — into a single governed document that states which influence path each control breaks, who owns it, what evidence proves it, and when it expires. Its defining feature is that it is a composition, not a control in its own right: it does not itself sever an asset or wall off a system, it decides which measures are proportionate to the specific matter and binds them together so the residual risk is knowingly accepted rather than left to chance. It exists precisely for the situations where disclosure alone is too weak and disqualification is too much.

Example

A university professor holds founder's equity in a startup and also proposes to run a clinical study whose results could raise or sink the company's value. Barring her from the study would waste the very expertise that makes it worth doing; letting her run it on a promise of objectivity is indefensible. The institution's conflict committee writes a management plan. It first scopes the matter — this study, its data analysis, its published conclusions, and the graduate students whose careers depend on her — and identifies the affected parties: the trial's patients and the journals' readers. Then it selects a bundle: an independent statistician analyzes the primary endpoint (so the equity-holder never touches the numbers that move the stock), an unconflicted co-investigator holds authority over enrollment and adverse-event reporting, her equity and the plan itself are disclosed in every resulting publication, and the arrangement is recorded with a named monitor and a review date tied to study completion.

The plan's payoff is that it converts an unmanageable "should she or shouldn't she" into a checkable structure: each way the equity could distort the science has a specific control against it, an owner, and a record an auditor or reader can later inspect.

How it works

  • Scope the matter and its affected parties first, so the bundle is built to cover the actual influence paths rather than a generic template.
  • Select up the hierarchy. For each path, choose the least burdensome control that reduces residual risk to the accepted level — combining disclosure, monitoring, restriction, firewall, or partial recusal as needed.
  • Assign owner, evidence, and expiry to every control, so no line in the plan is aspirational and none outlives the matter.
  • Record the residual risk and who accepted it, producing a document that doubles as the notice-and-challenge record for later review.

Tuning parameters

  • Bundle strength — how far up the control hierarchy the plan reaches. Stronger bundles cut more risk but cost more expertise and continuity; the plan's whole job is to find the proportionate point.
  • Residual-risk threshold — the level of leftover risk the plan is willing to accept. Lower thresholds force heavier bundles; the dial should be set by an independent authority, not the conflicted party.
  • Granularity — one blanket plan vs. a control mapped to each distinct influence path. Fine-grained plans are more defensible but heavier to administer and monitor.
  • Expiry and review trigger — whether the plan ends at a fixed date, at matter completion, or on a material change. Too long and it becomes a standing waiver; too short and it thrashes.

When it helps, and when it misleads

Its strength is proportionality: it lets scarce expertise stay at the table under controls tailored to the exact risk, avoiding both symbolic disclosure and reflexive exclusion. It also creates a single inspectable object that makes the reasoning defensible after the fact.

Its failure mode is the generic boilerplate plan — a copied template with vague owners, no real monitoring, and an open-ended or auto-renewing expiry, which launders a serious conflict into the appearance of management without changing any actual influence path.[n1] The classic misuse is treating the plan's existence as the mitigation, so that writing the document substitutes for enforcing it. The guarding discipline is that every control in the bundle must name an owner, an evidence artifact, and a fixed review trigger, and the plan must be approved by an authority independent of the conflicted party — a plan nobody verifies is a story, not a control.

How it implements the components

  • mitigation_hierarchy_and_selection_rule — its heart: it applies the least-restrictive-effective-control logic to pick and combine measures for each influence path.
  • conflict_scope_and_affected_party_map — it scopes the exact matter, linked decisions, and affected parties the bundle must cover before selecting controls.
  • decision_record_notice_and_challenge_path — the plan document itself is the reasoned record of what was decided, who accepted the residual risk, and how it can be challenged.

It does not implement recusal_and_decision_rights_transfer or information_firewall_and_access_control — the plan may *call for a recusal or a firewall, but those controls are executed by Role Separation and Decision Transfer and Information Firewall; this mechanism selects and assembles, it does not perform them.*

Editorial Notes

Form Classification

Form family: Representation, Specification & Plan

Rationale: Assembles a matter-specific bundle of proportionate controls — with owners, evidence, and an expiry — when no single measure covers all the influence paths but full disqualification is unnecessary, making its operative form a non-executable information artifact that externalizes static or prospective structure.

Independent corroboration: The frozen evidence defines Conflict Management Plan as 'Assembles a matter-specific bundle of proportionate controls — with owners, evidence, and an expiry — when no single measure covers all the influence paths but full disqualification is unnecessary', so its operative form is Representation, Specification & Plan.

Nearest alternative: Rule, Policy & Commitment — It externalizes a matter-specific prospective bundle of controls, owners, evidence, expiry, and accepted residual risk rather than imposing a general rule.

Review outcome: Independent reviewer agreement; medium confidence.

Origin Attribution

Primary origin: Law & Governance

Origin pattern: Cross-disciplinary synthesis

Present-day reach: Multi-domain

Rationale: Conflict-of-interest governance established matter-specific, documented combinations of disclosure, independent monitoring, altered responsibilities, firewalls, partial disqualification, and periodic review to reduce an identified influence risk without always excluding the person entirely.

Related originating lineages:

  • Accounting & Auditing — Independence frameworks contribute documented threat assessment, proportionate safeguards, monitoring, and residual-risk review.
  • Medicine & Healthcare — Research institutions standardized formal management plans for investigators whose expertise and financial interests overlap.

Review resolution: HHS conflict-of-interest rules require designated officials to review disclosures and select management conditions including public disclosure, independent monitoring, plan modification, disqualification, divestiture, or severance. GAO's independence framework likewise requires identifying threats and applying safeguards. These directly support a governance primary with healthcare and auditing as formative lineages.

Attribution caveat: Research institutions and audit professions institutionalized especially complete management-plan and safeguard forms, but law and governance are primary because regulation defines the conflict, authorizes proportionate remedies, and requires documented management.

Review outcome: Researched adjudication after independent review; high confidence.

Sources consulted:

Notes

[n1] "Paper mitigation" is the recognized failure in which a conflict is documented as managed while no control actually changes participation, access, or ownership — the hazard that management-plan and disclosure regimes are most often criticized for producing.