Corporate Compliance & Ethics Management Lawyer | Turning compliance obligations into a system you can actually run
Summary
Ethics and compliance advisory covers designing internal control systems, anti-corruption and fair trade compliance, whistleblower channels, and responding to regulator inquiries before they become enforcement actions. Companies that operate an active compliance program can also receive mitigated liability treatment in certain administrative and criminal contexts, which is why the design of the program matters as much as having one on paper. This page explains the main building blocks a company needs and where the legal risk usually concentrates.
Administrative · CorporateRelated law: 부정청탁 및 금품등 수수의 금지에 관한 법률Related law: 공정거래법
Corporate Compliance & Ethics Management | What a working compliance program actually needs
A compliance program that exists only as a policy binder rarely helps in an actual investigation. Regulators and courts look at whether the program was genuinely operating at the time of the misconduct.
Risk mapping before drafting policy
Before writing a code of conduct, we map where the company's actual exposure sits: subcontractor payments, entertainment expenses, public official contact points, or data handling. A generic template copied from another industry often misses the risks specific to the company's business model.
Board and management accountability
For listed companies and certain financial institutions, having a documented internal control framework can affect how liability is allocated between the company and individual officers under related statutes. We review whether the board's oversight structure is documented in a way that would hold up under scrutiny.
Training and enforcement records
A policy without evidence of training, monitoring, or enforcement is often treated as cosmetic. We advise on what records a company should be keeping so that, if an incident occurs, the company can demonstrate the program was more than a document sitting in a drawer.
Companies above a certain size are effectively expected to operate a functioning internal reporting channel, and mishandling a report can create separate legal exposure on top of the underlying misconduct.
Protecting the reporter
Retaliation against an internal reporter of certain public-interest violations can itself be sanctioned (공익신고자 보호법). We advise companies on how to structure a reporting process so that handling of a complaint does not itself create liability.
Investigation procedure design
How a report is investigated matters as much as whether it is investigated. We help set up a process that separates the fact-finding function from the decision-making function, and that documents the investigation in a way that can withstand later review.
Confidentiality and data handling
Internal investigations often involve employee personal data, which raises separate obligations under data protection rules (개인정보 보호법). We review the interview and evidence-collection process so it does not itself create a secondary violation.
Corporate Compliance & Ethics Management | Anti-corruption, gift and entertainment rules, and fair trade exposure
Two areas generate a disproportionate share of compliance incidents in practice: improper solicitation or gifts involving public officials, and fair trade issues in dealings with subcontractors or distributors.
Gifts, entertainment, and public officials
The Improper Solicitation and Graft Act sets monetary limits and prohibited categories for gifts, meals, and congratulatory or condolence money involving public officials, and certain private-sector employees such as journalists and school staff (부정청탁 및 금품등 수수의 금지에 관한 법률). We advise companies on setting internal thresholds that stay comfortably inside the statutory limits, since a violation can expose both the individual employee and, in some structures, the company.
Fair trade compliance with subcontractors
Unfair practices toward subcontractors or distributors, such as unilateral price adjustments or delayed payment, can trigger review under the Fair Trade Act and the Subcontracting Act (공정거래법, 하도급법). We review standard contract terms and pricing practices for provisions that regulators commonly flag.
Responding to a regulator inquiry
When a company receives an inquiry or on-site inspection notice from a regulator such as the Korea Fair Trade Commission or the Anti-Corruption and Civil Rights Commission, how the first response is handled often shapes the rest of the proceeding. We advise on document preparation and communication strategy at that early stage.
Corporate Compliance & Ethics Management | From risk diagnosis to an operating compliance system
1
Initial risk diagnosis We review the company's industry, transaction structure, and existing policies to identify where legal exposure actually concentrates, rather than starting from a generic checklist.
2
Gap analysis against current policy If a code of conduct or compliance manual already exists, we compare it against current statutory requirements and flag where it is outdated or unenforced.
3
Program and document drafting We draft or revise the code of conduct, internal reporting procedure, and related approval processes so they reflect how the company actually operates day to day.
4
Training and rollout support We support management-level and employee-level training sessions so the program is documented as having been actually communicated, not just issued.
5
Ongoing monitoring and incident response For companies on a continuing advisory basis, we provide periodic review and are available when an internal report or regulator inquiry arises.
Corporate Compliance & Ethics Management | How advisory fees are typically structured
One-time diagnosis fee A fixed fee based on the scope of the initial risk diagnosis and document review, generally scaled to company size and number of business units reviewed.
Program drafting fee Calculated based on the number and complexity of policy documents drafted, such as a code of conduct, reporting procedure, and approval matrix.
Retainer for ongoing advisory Companies that want continuing access to advice on compliance questions and incident response typically enter a monthly or annual retainer, scoped to expected inquiry volume.
Incident-specific response fee If an internal report or regulator inquiry arises during the engagement, work on that specific matter is generally billed separately from the base retainer, depending on scope.
※ Costs vary depending on case complexity and specific circumstances; exact fees will be provided during consultation. No specific outcome is guaranteed.
Corporate Compliance & Ethics Management | Self-Check Before You Call
1️⃣ For Business Owners and Executives
Does your company have a written code of conduct that employees can actually locate and read?
Have you set internal limits on gifts and entertainment involving public officials or business partners?
If a regulator called tomorrow asking for documents, could you produce them within the deadline?
Do you know which of your officers is personally exposed if a compliance failure is found?
2️⃣ For Compliance Officers
Is your internal reporting channel actually used, or has it received zero reports in the past year?
Do you have a documented process for investigating a report that keeps fact-finding separate from disciplinary decision-making?
Are your training records sufficient to show the program was communicated, not just published?
Have your subcontractor and distributor contracts been reviewed for fair trade compliance in the last two years?
3️⃣ If You Have Already Received a Regulator Inquiry
Have you identified exactly which documents the inquiry is requesting, and by when?
Have you preserved relevant records rather than allowing routine deletion schedules to run?
Is there a single point of contact managing communication with the regulator?
Have you assessed whether individual officers, not just the company, face separate exposure?
Frequently Asked Questions
Q. Is our company legally required to have a compliance program?
A. There is no single statute requiring every company to have a compliance program, but certain sectors such as financial institutions and listed companies face specific internal control requirements, and having a documented program can affect liability treatment in other statutes. Whether a program is effectively mandatory depends on your industry and company size.
Q. What is the difference between a compliance program and a code of ethics?
A. A code of ethics is usually a short statement of values, while a compliance program includes the operational processes behind it, such as approval workflows, reporting channels, training records, and monitoring. A company can have the former without the latter, which is often where problems arise during an actual investigation.
Q. Can our company be held liable for an employee's individual violation of the Improper Solicitation and Graft Act?
A. Under certain structures, the company can face administrative or criminal exposure alongside the individual employee if the violation occurred in the course of business and the company failed to take reasonable preventive measures (부정청탁 및 금품등 수수의 금지에 관한 법률). Whether that exposure attaches depends on the specific facts and the company's existing controls.
Q. What should we do if an employee reports misconduct internally?
A. The report should go through a defined investigation process that keeps fact-finding separate from disciplinary decisions, and retaliation against the reporter of certain public-interest violations can itself be sanctioned (공익신고자 보호법). Mishandling the process can create a second legal problem on top of the original issue reported.
Q. How should we respond if we receive an on-site inspection notice from the Fair Trade Commission?
A. The first step is identifying exactly what documents and time period the inspection covers and preserving relevant records rather than allowing routine deletion. How the company communicates and cooperates during the initial stage often affects how the rest of the proceeding unfolds.
Q. Do our contracts with subcontractors need to be reviewed for fair trade compliance?
A. Provisions on payment timing, price adjustment, and unilateral contract changes are commonly scrutinized under the Fair Trade Act and Subcontracting Act (공정거래법, 하도급법). A periodic contract review can catch clauses that were standard practice years ago but are now treated as problematic.
Q. How often should our compliance program be updated?
A. There is no fixed statutory interval, but a program that has not been reviewed in several years often no longer matches current regulation or the company's actual operations. Many companies review core policies annually and revisit them sooner after a relevant regulatory change or internal incident.
Q. What happens if we build a program only after an incident has already occurred?
A. A program adopted after an incident cannot retroactively excuse that specific incident, but a credible response, including corrective measures and a going-forward program, is often relevant to how a regulator or court evaluates the company's overall conduct. Timing and substance both matter in how this is received.
Q. Can a company advisory lawyer represent us if a compliance issue turns into a formal investigation?
A. Advisory work and investigation defense are related but distinct; if a matter escalates to a formal regulatory or criminal investigation, a company typically needs representation with litigation and investigation experience rather than only preventive advisory support. We can discuss which scope fits your situation at the initial consultation.
법무법인 프런티어(이하 “사무소”)는 개인정보보호법에 따라 정보주체의 개인정보 및 권익을 보호하고 개인정보와 관련된 정보주체의 고충을 신속하고 원활하게 처리하기 위하여 본 개인정보 처리방침을 수립·공개합니다.
제 1 조 수집하는 개인정보의 항목, 목적, 방법
제 2 조 개인정보의 처리 및 보유기간
제 3 조 개인정보의 제3자 제공
제 4 조 개인정보 처리업무의 위탁
제 5 조 정보주체의 권리·의무 및 그 행사방법
제 6 조 개인정보의 파기
제 7 조 의견수렴 및 불만처리
제 8 조 개인정보 처리방침의 변경
제 9 조 개인정보의 안전성 확보 조치
제 1 조 (수집하는 개인정보의 항목, 목적, 방법)
① 게시판 글 작성 시 필수 항목에 대한 수집목적은 ‘별도의 구체적 상담을 위하여’이며 수집항목은 ‘이름, 이메일, 연락처’입니다.
② 전항 외에 고객의 서비스 이용 과정이나 요청 사항 처리 과정에서 ‘IP주소, 접속로그, 단말기 및 환경정보, 서비스 이용기록, 쿠키’와 같은 정보들이 자동으로 수집 및 저장될 수 있으며, 이 때의 수집목적은 ‘사용자 홈페이지 이용, 사이트 이용에 대한 문의 민원 등 고객 고충 처리’입니다.
③ 사무소는 ‘홈페이지 고객 문의/고충 처리 시 전화 또는 인터넷을 통한 상담’과 같은 방법으로 개인정보를 수집합니다
제 2 조 (개인정보의 처리 및 보유기간)
관계법령의 규정에 따라 개인정보를 보존하여야 하는 의무가 있는 경우가 아닌 한, 정보주체의 개인정보는 원칙적으로 해당 개인정보의 처리목적이 달성될 때까지 보유 및 이용되며, 그 목적이 달성되면 지체 없이 파기됩니다.
제 3 조 (개인정보의 제3자 제공)
사무소는 정보주체의 개인정보를 본 처리방침에서 명시한 목적에 한해서만 처리하며 정보주체의 사전동의가 있는 경우 또는 개인정보보호법 등 관계법령의 규정에 의거한 경우에만 개인정보를 제3자에게 제공합니다. 사무소는 현재 개인정보를 제3자에게 제공하지 않고 있습니다.
제 4 조 (개인정보 처리업무의 위탁)
사무소는 현재 귀하의 개인정보 보호를 위해 귀하의 개인정보를 직접 취급 관리하고 있습니다. 단, 향후 보다 전문적인 서비스를 제공하기 위하여 제3의 전문기관에 귀하의 정보를 위탁할 필요가 있다고 판단되는 경우, 귀하의 사전 동의 하에 개인정보에 대한 취급을 위탁할 수 있습니다.
제 5 조 (정보주체의 권리·의무 및 그 행사방법)
① 정보주체는 개인정보보호법 등 관계법령이 정하는 바에 따라 사무소에 대해 개인정보의 열람, 정정 및 삭제, 처리정지 요구 등 개인정보 보호 관련 권리를 행사할 수 있습니다.
② 제1항에 따른 권리행사는 정보주체의 법정대리인이나 위임을 받은 사람을 통해서도 할 수 있습니다. 다만, 이 경우에는 개인정보보호법 시행규칙에 따른 위임장을 사무소에 제출하여야 합니다.
③ 사무소는 정보주체의 권리행사에 대하여 개인정보보호법 등 관계법령이 정하는 바에 따라 지체 없이 조치하겠습니다.
제 6 조 (개인정보의 파기)
① 사무소는 원칙적으로 개인정보의 처리목적이 달성된 경우 등 그 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.
② 사무소가 관계법령의 규정에 따라 개인정보를 파기하지 아니하고 보존하여야 하는 경우에는 해당 개인정보 또는 개인정보파일을 다른 개인정보와 분리해서 저장·관리 합니다.
③ 사무소는 파기사유가 발생한 개인정보를 선정하여 개인정보 보호책임자의 승인을 받아 해당 개인정보를 파기합니다.
④ 사무소는 파기하여야 할 개인정보가 전자적 파일 형태인 경우 복원이 불가능한 방법으로 영구 삭제하며, 이외의 기록물, 인쇄물, 서면, 그 밖의 기록매체인 경우 파쇄 또는 소각합니다.
제 7 조 (의견수렴 및 불만처리)
정보주체는 개인정보 보호 관련 문의, 불만처리, 피해구제 등에 관한 사항을 아래 개인정보 보호책임자 또는 담당부서에 문의하실 수 있습니다. 사무소는 정보주체의 문의에 대하여 신속하고 충분한 답변을 드릴 것입니다.
개인정보 보호 책임자 : 변호사
연락처 : 02.
제 8 조 (개인정보 처리방침의 변경)
사무소의 개인정보 처리방침은 관련 법령, 지침 및 사무소 내부규정에 따라 변경될 수 있으며, 개인정보 처리방침이 변경되는 경우 관련 법령이 정하는 방법에 따라 공개합니다.
제 9 조 (개인정보의 안전성 확보 조치)
사무소는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
관리적 조치 : 내부관리계획의 수립 및 시행, 구성원에 대한 정기적인 개인정보 보호교육 등
기술적 조치 : 개인정보처리시스템 등의 접근권한 관리, 접근통제시스템 설치, 고유식별정보 등의 암호화, 보안프로그램의 설치 등
물리적 조치 : 전산실, 자료보관실 등 개인정보 보관장소에 대한 접근통제