
Ethics and Compliance
Why It Matters | Our Approach | Resources | Related Topics
Last updated: July 1, 2026
Why It Matters
To Lilly
Ethics and compliance are central to how we operate and make decisions. Our strong ethical culture reinforces accountability and transparency, empowering people to speak up and do what’s right, while supporting responsible innovation and sustainable performance.
To the World
A strong ethical foundation supports the safe development and delivery of medicines, protects patient interests, and reinforces trust in how we operate across diverse markets and regulatory environments. When we act ethically, we strengthen relationships, contribute positively to the communities we serve, and sustain confidence in our ability to make a meaningful, lasting impact on global health.
Approach
We are committed to upholding high standards of corporate conduct across our global operations. Our code of business conduct, policies, compliance management systems, performance practices, training, and communications work together to promote ethical behavior and reinforce a strong culture of integrity.
We continuously assess and improve our ethics and compliance program. The program includes board-level and management oversight, proactive risk assessments, written standards, training and communications, reporting, proactive monitoring, auditing, and investigations processes designed to reduce risk, enhance compliance, and prevent fraud and other regulatory or policy violations. The ethics and compliance function supports global anti-corruption, integrated risk management, and business continuity efforts.
Transparency is a key part of how we work. By openly disclosing how we collaborate with health care professionals, patient advocacy groups, and other stakeholders, we build trust and demonstrate our commitment to working responsibly to benefit the people we serve.
Board-Level Oversight
Our Chief Ethics and Compliance Officer is responsible for designing, implementing, and overseeing the company's ethics and compliance program, with reporting obligations to the CEO and regular updates to the full Board of Directors, Ethics and Compliance Committee, and Audit Committee of the Board.
The Chief Ethics and Compliance Officer presents an annual State of Compliance report to the full Board of Directors, providing independent oversight and transparency into the effectiveness of the ethics and compliance program. The report informs the Board of key risks, trends, program performance, and significant matters, enabling informed governance and strategic direction.
In bi-annual joint meetings, the Ethics and Compliance Committee and Audit Committee review relevant topics including compliance metrics, corporate audit progress, health, safety, and quality outcomes, and the evolving external compliance environment.
The Ethics and Compliance Committee meets quarterly to review legal and regulatory trends, as well as compliance and quality matters that may impact the company. When necessary, they escalate to the full Board.
Risk Management
Risks are identified by leaders across the business as part of business planning and ongoing operations, then assessed and prioritized by potential impact and likelihood. The Board, directly and through its committees, receives reports on the company's enterprise risks, including risk identification, assessment, and mitigation oversight. Enterprise-level risks are reviewed at least annually at a full board meeting and also addressed in periodic business function reviews and senior management strategy sessions, ensuring ongoing board-level visibility into the company's enterprise risk landscape.
Written Standards
Our written standards, including our code of business conduct, policies, and procedures, reinforce our core values and provide guidance on how we expect business to be conducted. These standards outline appropriate interactions with health care providers, government officials, and other external parties. They are designed to be consistent with recognized industry codes, such as those issued by the International Federation of Pharmaceutical Manufacturers & Associations (IFPMA), the Pharmaceutical Research and Manufacturers of America (PhRMA), and numerous regional/local codes in the markets in which we operate.
The Red Book Code of Business Conduct sets clear expectations for employee behavior. It outlines how we put our values into action and serves as a practical guide for making ethical decisions in daily work. The Code includes 11 responsibility statements reflecting our approach to ethical business practices and responsible conduct across all areas of our operations. To ensure accessibility across our global organization, the Red Book is available in 19 languages.
Training and Communications
We believe ethics and compliance are the responsibility of every employee, which is why training and communications are essential to nurturing a strong culture of integrity.
Each year, we require our employees to complete code of business conduct training and certify they have read, understood, and will abide by its requirements. We also maintain appropriate training expectations for contingent workers and vendors. Failure to complete the training by the established deadline may result in disciplinary action, including potential impact to bonus eligibility. In 2025, 99.9% of employees completed Red Book Code of Business Conduct training prior to the due date. Most employees receive additional targeted ethics and compliance training related to their specific role, typically including real-world scenarios and case studies that help employees recognize common workplace compliance situations and apply sound ethical decision-making.
Additionally, we use communications to help leaders and employees understand their responsibilities, access relevant resources, share best practices, and reflect on lessons learned, reaching our global workforce across a range of internal channels.
Tracking Our Progress
We measure the effectiveness of our efforts through a combination of global employee surveys, questions asked through helplines, our Ethics and Compliance Officers and chatbot, training completion rates, knowledge assessments, and monitoring of reported violations. These metrics help us assess awareness, understanding, and behavior across the organization and continuously enhance our initiatives.
Reporting
To help identify possible compliance issues, we maintain an internal disclosure system that includes a mechanism for anonymous reporting, where permitted by local law.
Internal Reporting - Speaking up is both a right and a responsibility at Lilly. Employees are required to report known or suspected violations of the Red Book Code of Business Conduct, company policies or procedures, laws, regulations, and applicable industry association codes. We actively encourage employees to raise ethical concerns, including those related to harassment and discrimination. Anyone, inside or outside the company, can submit a concern at speakup.lilly.com via an online form or toll-free telephone option. The phone line is staffed by an independent firm and available 24 hours a day, seven days a week, with translation services available. Reports may be made anonymously, subject to local law.
Employees are actively encouraged to bring concerns to supervisors, leaders and representatives of ethics and compliance, legal and human resources. Retaliation against individuals who report concerns in good faith or participate in investigations is strictly prohibited.
In our 2025 global survey, 76% of employees indicated they are willing to speak up about issues they observe or experience without fear of retaliation and 81% trust that when violations are reported, they are investigated thoroughly and addressed appropriately. These results reflect an environment where employees feel supported in raising concerns and confident that those concerns will be taken seriously.
External Inquiries - From time to time, we receive external inquiries and letters from regulatory bodies such as the US Food and Drug Administration (FDA). We respond to them and implement corrective actions as appropriate.
Monitoring and Auditing
Monitoring - We maintain a risk-based ethics and compliance monitoring program. Key components include advanced data analytics and responsible use of artificial intelligence, risk assessments, proactive monitoring plans and standardized tools and processes for reporting metrics to business and functional leaders.
Auditing - Our internal auditing functions conduct financial, nonfinancial and quality audits of Lilly affiliates, functions, and manufacturing and research operations, as well as certain third parties to evaluate compliance with our policies and procedures. Audits are prioritized using a risk-based methodology leveraging data analytics and are influenced by the results of the annual Integrated Risk Management (IRM) process aligned with the company’s strategic plan. Audits include reviews of our anti-corruption program, privacy and other policies related to ethical interactions (e.g., off-label promotion).
Assurance Governance – To align and integrate our audit and assessment activities, we operate an Assurance Governance Forum - comprised of leaders from ethics and compliance, internal audit, quality, third party risk management, and information security. The forum provides integrated leadership to ensure that our risk and compliance programs meet stakeholder expectations and deliver maximum value and efficiency, sharing learnings and insights with senior leadership and the Board of Directors.
Investigations and Remediation Actions
We take all reports of possible misconduct seriously. When someone reports potential wrongdoing or we detect it through proactive monitoring, we investigate and identify root causes as needed. In 2025 we received 3,012 reports of potential issues across all reporting channels globally (e.g., speakup.lilly.com, email, personal contact) and identified an additional 740 matters through proactive monitoring for investigative follow-up. Following an investigation, we help business owners identify and implement remediation actions designed to address the issues and prevent recurrence. We monitor the effectiveness of these actions, adjust as needed, and track and report our progress.
Our global investigations team is specially trained to handle these matters, following a risk-tailored process that meets privacy and legal requirements around the world.
Anti-Corruption Compliance
Our approach to operating with high ethical standards includes complying with applicable Anti-Bribery and Anti-Corruption (ABAC) laws and regulations, extending to business relationships, dealings and activities globally. Our policies prohibit bribery, fraud and other acts of dishonesty - including that we do not offer, provide, authorize or accept anything of value, or give the appearance that we do, to inappropriately influence a decision or gain an unfair advantage. This also extends to our work with third parties.
We use a risk-based anti-corruption due diligence process to evaluate certain third parties before engaging them, including those who may be authorized to interact with health care providers or government officials on our behalf, prospective recipients of grants and donations, and prospective business development partners. As determined through our risk evaluation process, third parties may be required to follow our anti-corruption requirements and participate in anti-corruption training. We conduct independent ABAC assessments of certain third parties, which often include site visits and transaction testing, as well as an annual global anti-corruption risk assessment to identify potential risks and develop appropriate risk mitigation plans.
Resources
