Legal · Governance Register · Public Document

Policies & Procedures.

The full register of the policies and procedures by which Executive Search operates. Each entry sets out purpose, scope, principles, procedure, controls, the evidence we retain, and the regulatory regimes the policy is aligned to. The register is reviewed on a published cycle and is auditable on request.

15
Policies in register
7
Policy categories
Annual / Semi-annual
Review cadence
7 years
Audit trail retention
ES-POL-001Engagement & MandateOwner · Group Managing PartnerCycle · AnnualLast reviewed · 2026-03-14Effective from · 2026-04-01

Board-Grade Engagement & Mandate Acceptance

Define the criteria, conflicts screening, and ratification path under which Executive Search accepts mandates from chairs, nomination committees, institutional investors, and regulators.

Authority · Partnership Council resolution PC-2026-04
ES-POL-002Conduct & EthicsOwner · General CounselCycle · AnnualLast reviewed · 2026-02-20Effective from · 2026-03-01

Discretion, Confidentiality & Non-Disclosure

Codify Executive Search's NDA-by-default posture and the operational controls that preserve the discretion required by chairs, sitting CEOs, and institutional investors.

Authority · Partnership Council resolution PC-2026-02
ES-POL-003Information SecurityOwner · Chief Scientist (delegated: Head of Platform Security)Cycle · Semi-annualLast reviewed · 2026-04-30Effective from · 2026-05-15

Information Security & Cryptographic Controls

Govern the protection of client data, candidate data, telemetry artefacts, and proprietary models against unauthorised access, modification, or exfiltration.

Authority · ISO 27001 certified Information Security Management System
ES-POL-004Data & PrivacyOwner · Chief Regulatory ArchitectCycle · AnnualLast reviewed · 2026-01-18Effective from · 2026-02-01

Data Residency, Sovereignty & Cross-Border Transfer

Ensure that engagement data is stored, processed, and accessed in jurisdictions consistent with client mandates, regulatory requirements, and the firm's NDA-by-default posture.

Authority · Jurisdictional Data Residency Framework JDR-v3
ES-POL-005GovernanceOwner · Chief ScientistCycle · Semi-annualLast reviewed · 2026-05-02Effective from · 2026-05-15

Algorithmic Auditability & Model Governance

Ensure every model used in board-grade decisions — succession ranking, derailment-risk vectors, skills-mix drift, candidate-slate construction — is auditable, bias-controlled, and defensible to clients, regulators, and litigants.

Authority · Model Governance Council charter
ES-POL-006Data & PrivacyOwner · General CounselCycle · AnnualLast reviewed · 2026-02-04Effective from · 2026-03-01

Candidate Data, Consent & Right of Access

Define how Executive Search lawfully collects, processes, retains, and discloses candidate-identifying data for assessment, succession, and search engagements.

Authority · Global Candidate Data Charter CDC-v2
ES-POL-007Conduct & EthicsOwner · General CounselCycle · AnnualLast reviewed · 2026-03-09Effective from · 2026-04-01

Anti-Bribery, Anti-Corruption & Gift Restriction

Prohibit bribery and corruption in any form and prevent the appearance of impropriety through bright-line gift, hospitality, and political-contribution rules.

Authority · Partnership Council resolution PC-2026-06
ES-POL-008Conduct & EthicsOwner · General Counsel (with Partnership Council oversight)Cycle · AnnualLast reviewed · 2026-01-25Effective from · 2026-02-15

Whistleblower Protection & Speak-Up

Establish protected, independent channels through which employees, partners, contractors, candidates, and clients may raise concerns about misconduct, fraud, regulatory breach, or unethical behaviour.

Authority · Partnership Council resolution PC-2026-01
ES-POL-009Conduct & EthicsOwner · General CounselCycle · AnnualLast reviewed · 2026-02-12Effective from · 2026-03-01

Conflicts of Interest & Outside Activities

Prevent personal, financial, or relationship interests from compromising the firm's empirical, independent posture.

Authority · Partnership Council resolution PC-2026-03
ES-POL-010GovernanceOwner · Chief of Practice OperationsCycle · AnnualLast reviewed · 2026-03-22Effective from · 2026-04-01

Diversity, Equity, Inclusion & Anti-Bias

Embed empirical anti-bias controls in every assessment, search, and succession decision, and hold the firm itself to a measured, transparent standard.

Authority · Partnership Council resolution PC-2026-05
ES-POL-011Operational ResilienceOwner · Chief of Practice OperationsCycle · AnnualLast reviewed · 2026-04-12Effective from · 2026-05-01

Business Continuity & Operational Resilience

Ensure continuous availability of board-grade engagement services through disruption — including infrastructure outage, geopolitical disruption, pandemic, and supplier failure.

Authority · Operational Resilience Framework ORF-v4
ES-POL-012GovernanceOwner · General CounselCycle · AnnualLast reviewed · 2026-02-28Effective from · 2026-04-01

Records Retention, Destruction & Litigation Hold

Set the retention, destruction, and legal-hold rules for every category of record the firm holds, balancing audit defensibility with data-minimisation obligations.

Authority · Records Management Framework RMF-v2
ES-POL-013Operational ResilienceOwner · Chief of Practice OperationsCycle · AnnualLast reviewed · 2026-03-30Effective from · 2026-04-15

Procurement, Third-Party Risk & Vendor Due Diligence

Ensure that every third party handling firm or client data, providing critical infrastructure, or acting on the firm's behalf is subject to risk-based due diligence and continuous oversight.

Authority · Third-Party Risk Management Framework TPRMF-v2
ES-POL-014Regulatory & DisclosureOwner · General Counsel (with Chief Scientist for technology events)Cycle · Semi-annualLast reviewed · 2026-04-08Effective from · 2026-05-01

Incident Response & Regulator Notification

Govern detection, containment, investigation, notification, and learning from incidents — privacy, security, operational, ethical, or regulatory.

Authority · Incident Response Runbook IRR-v5
ES-POL-015Regulatory & DisclosureOwner · General CounselCycle · Semi-annualLast reviewed · 2026-05-06Effective from · 2026-05-20

Sanctions, Export Control & Politically Exposed Persons

Ensure the firm does not act for, place, or process data of sanctioned parties, and that politically exposed persons are subject to heightened due diligence.

Authority · Sanctions & PEP Framework SPF-v3
Document Control

This register is maintained by the General Counsel. Material amendments are ratified by the Partnership Council and the effective date is set explicitly per policy. Historical versions are retained for the lifetime of the firm and are available to clients and regulators on request.

Audit & Assurance
  • ISO/IEC 27001:2022 certified.
  • SOC 2 Type II audited annually.
  • Independent algorithmic review every 24 months.
  • Whistleblower channel independently operated.
Request & Disclosure

Clients, regulators, and prospective clients may request the underlying policy documents, evidence packages, or attestations in full. Requests are handled under the Discretion Protocol set out in ES-POL-002.