Compliance & Governance

Corporate policies we operate by.

PROUD TO PRESENT (Professor Healthcare Co., Ltd.) maintains formal, signed policies and controls for ethical, transparent business conduct as a partner to pharmaceutical and vaccine companies. Policy summaries are published below; signed full versions are available for download.

Anti-Bribery & Anti-Corruption (ABAC) Policy

Zero tolerance · Includes fraud & economic crime prevention

Professor Healthcare Company Limited prohibits bribery, corruption, fraud, and all other economic crimes in any form, whether involving public officials, healthcare professionals, or private parties. We comply with applicable anti-bribery, anti-corruption, and fraud-prevention legislation, including Thai law, the UK Bribery Act 2010, the UK Criminal Finances Act 2017, the UK Economic Crime and Corporate Transparency Act 2023, and the US Foreign Corrupt Practices Act 1977, each as amended.

  • No offering, giving, soliciting, or accepting of bribes, kickbacks, or facilitation payments of any value, directly or through third parties.
  • Interactions with healthcare professionals and government officials are conducted transparently, with legitimate purpose, and in line with applicable industry codes.
  • Risk-based due diligence is performed on suppliers, subcontractors, and business partners before engagement.
  • All transactions are recorded accurately and completely in our books and records; no off-book accounts are permitted.
  • Fraud risks are assessed as part of project and financial controls; suspected fraud is investigated and addressed without exception.
  • All staff receive ABAC awareness briefings; violations result in disciplinary action up to termination and referral to authorities.
Code of Conduct

Integrity in every engagement

Our Code of Conduct sets the standard of behaviour expected of every director, employee, and contractor acting on behalf of the company.

  • Comply with all applicable laws, regulations, and relevant industry codes governing the promotion of medicines and vaccines, in every market where we support clients.
  • Act honestly and transparently with clients, suppliers, healthcare professionals, and authorities; never make misleading claims in any material we produce.
  • Protect confidential client information and personal data in accordance with Thailand's Personal Data Protection Act (PDPA) and contractual obligations.
  • Respect all individuals: no discrimination, harassment, or abuse of any kind is tolerated.
  • Avoid situations where personal interests conflict, or appear to conflict, with the interests of the company or its clients; declared conflicts are managed and documented.
  • Raise concerns about possible misconduct through management channels; reports are handled confidentially and without retaliation.
Hospitality & Gifts Policy

Modest · Transparent · Never to influence

Hospitality and gifts may only ever be modest, reasonable, infrequent, and given or received openly for a legitimate business purpose. They must never be offered or accepted to improperly influence a decision.

  • Cash or cash equivalents (gift cards, vouchers) are prohibited in all circumstances.
  • Hospitality connected to healthcare professionals must comply with applicable healthcare industry codes and client compliance policies, and is limited to what is permitted for scientific or educational engagement.
  • Business meals and event hospitality must be proportionate, secondary to the business purpose, and accurately recorded.
  • Gifts or hospitality above defined value thresholds require prior written approval from the Managing Director and are logged in a gifts & hospitality register maintained by the Project, Third-Party & Records Focal Point.
  • Anything offered during tender periods or contract negotiations must be declined and reported.
Expenses Policy & Procedures

Legitimate · Documented · Approved

All business expenses must serve a legitimate, documented business purpose and be incurred, approved, and recorded under controlled procedures.

  • Expenses are supported by original receipts or tax invoices and a stated business purpose, and are submitted through a standard claim process.
  • Approval is required from the responsible manager before reimbursement; the Managing Director approves expenses above defined thresholds.
  • Client-billable costs are recorded transparently against the relevant project and are supported by evidence made available to clients.
  • Entertainment or hospitality expenses must additionally comply with the Hospitality & Gifts Policy; disguising such costs under other categories is prohibited.
  • All expenses are recorded accurately in the accounting system, supporting complete and auditable books and records.
Procurement & Buying Policy & Procedure

Fair selection · Supplier due diligence

We buy goods and services fairly, transparently, and on merit, ensuring suppliers meet our ethical, quality, and data-protection standards — particularly where they support work for pharmaceutical and vaccine clients.

  • Purchases above defined thresholds require competitive quotations from multiple suppliers, evaluated on quality, capability, compliance, and value.
  • Staff involved in purchasing must declare any personal interest in a supplier; conflicted individuals are removed from the decision.
  • Supplier due diligence is performed before onboarding, including verification of legal registration, and anti-bribery expectations are communicated and flowed down contractually.
  • Suppliers handling personal data or client materials must meet PDPA and confidentiality requirements.
  • Purchase orders, goods receipt, and invoice approval are segregated where practicable, and payments are made only against approved documentation.
Compliance Programme, Risk Assessment & Monitoring

Documented · Monitored · Anti-bribery, anti-fraud & anti-tax evasion

We operate a documented and monitored compliance programme designed to prevent, detect, and investigate potential misconduct and non-compliance with our policies, covering bribery, corruption, fraud, facilitation of tax evasion, and other economic crimes.

  • An annual compliance risk assessment reviews bribery, fraud, and tax-evasion risks across clients, projects, suppliers, and payment flows; identified risks are rated and assigned mitigating controls.
  • Financial controls include segregation of duties, dual approval of payments, supplier verification, and monthly management review of accounts.
  • The Managing Director is accountable for the programme and operates the financial controls directly, supported by the company’s licensed external accountants; record-keeping and registers are segregated to the Project, Third-Party & Records Focal Point, so no single person both records and approves a transaction without review.
  • Suspected misconduct is investigated promptly, documented, and remediated; serious matters are escalated to external advisors or authorities as appropriate.
  • The programme, policies, and risk register are reviewed at least annually and after any significant incident or business change.
Whistleblowing & Speak-Up Policy

Open to staff, subcontractors, partners & the public · Anonymous reporting accepted

We maintain a speak-up mechanism through which integrity-related concerns can be raised — anonymously or otherwise — by anyone: our employees, permitted subcontractors, third-party agents, clients, or members of the general public.

  • Concerns may be reported by email to sutiwas@proudtopresent.net, in writing to our registered office, or verbally to any manager; anonymous reports are accepted and treated with equal seriousness.
  • All reports are logged, acknowledged, and assessed by the Managing Director (or an alternate reviewer where the concern involves the Managing Director).
  • Investigations are conducted fairly, confidentially, and without conflict of interest; findings and corrective actions are documented.
  • Retaliation against anyone who raises a concern in good faith is strictly prohibited and is itself a disciplinary offence.
  • Outcomes are tracked to closure and reported in the annual compliance review.
Management Oversight, Issue Resolution & Internal Audit

Assess · Track · Resolve · Audit

Management oversight procedures ensure that issues of misconduct or non-compliance are assessed, tracked, and resolved, and that internal audits verify compliance with applicable legal, regulatory, and industry requirements — including anti-bribery, anti-corruption, and prevention of fraud and tax evasion.

  • A compliance issue log records every identified issue with its risk rating, owner, corrective action, and target date; open items are reviewed monthly by the Managing Director.
  • Root-cause analysis is performed for significant issues, and controls or training are updated to prevent recurrence.
  • An internal audit programme reviews, at least annually, financial records, expenses, procurement files, gifts & hospitality registers, and project documentation against our policies and applicable law.
  • Audit findings and remediation status are documented and reported to management; external accountants provide independent review of statutory financial statements.
  • Results feed back into the annual risk assessment and policy review cycle.
Data Protection & Privacy Policy

PDPA-aligned · Processor on client instructions · 72-hour breach notification

We process personal data in accordance with Thailand's Personal Data Protection Act B.E. 2562 (PDPA) and, where relevant to client engagements, principles equivalent to the GDPR. In most engagements we act as a data processor, handling personal data only on the documented instructions of our client.

  • A designated Data Privacy contact monitors compliance with all data privacy obligations: the Managing Director, sutiwas@proudtopresent.net.
  • Data minimisation applies — we collect only what the agreed service requires (e.g. participant name, affiliation, and contact details for event registration) and never use client data for marketing or secondary purposes.
  • Personal data breaches are reported to the affected client without undue delay and in any event within 72 hours of becoming aware, with all information reasonably available; a breach register tracks each incident to closure.
  • Data subject requests received in a processor role are forwarded to the client within 3 business days, with our full assistance in responding.
  • Personal data is retained only as long as required, then securely deleted or returned to the client; cross-border transfers require a lawful basis and the client's prior authorisation.
Access Control & Information Security Policy

Need-to-know access · Six-monthly review · Prompt revocation · Annual testing

Access to personal data and client information is granted strictly on a need-to-know basis, reviewed regularly, and revoked promptly when people leave or engagements end.

  • Access is requested by the project manager, approved by the Managing Director, and recorded in an access register maintained by the Project, Third-Party & Records Focal Point; sub-agents and sub-contractors receive access only after signing confidentiality and data protection undertakings.
  • A formal review of all access permissions is performed at least every six months, verifying that each account is still necessary and holds the minimum required privilege; excessive permissions are removed immediately.
  • Access for terminated employees, sub-agents, and sub-contractors is revoked on the last working day and in any event within 24 hours, following a documented off-boarding checklist covering accounts, email, cloud storage, devices, and data return.
  • Technical measures include multi-factor authentication, device and transit encryption, role-based cloud folder permissions, endpoint protection, secure file transfer, and backups with restoration checks.
  • Technical and security controls are tested at least annually — including access verification, backup restoration, authentication settings, and a breach-response walkthrough — with findings tracked to closure.
Third-Party & Sub-processor Management Policy

Due diligence · Contractual flow-down · Annual re-assessment

Third parties who may access client information or personal data — sub-contractors, sub-agents, freelancers, and technology suppliers — are assessed before engagement and bound by terms no less protective than those we owe our clients.

  • Pre-engagement due diligence covers legal registration, capability, confidentiality practices and, where personal data is involved, storage location, access controls, sub-contracting, and breach-notification capability.
  • Written agreements impose confidentiality, purpose limitation, security measures, no unauthorised sub-contracting, assistance with data subject requests, and return or deletion of data on completion.
  • Third parties must notify us of any suspected personal data breach within 24 hours, enabling us to meet our own 72-hour obligation to the client.
  • Third parties with access to personal data are re-assessed at least annually, or upon any material change, incident, or change in data access; their access is included in the six-monthly access review.
  • Where a third party supports a client engagement, we disclose that party's identity and role to the client and obtain any required authorisation before access is granted.
ABAC Roles & Responsibilities

Named accountability · Three lines of control · Annual review

Responsibility for anti-bribery, anti-corruption, anti-fraud, and anti-tax-evasion risk is formally allocated to named individuals, each of whom has been informed of and has accepted their responsibilities in a signed acknowledgement record.

  • ABAC Compliance Owner — Managing Director: ultimate accountability for the programme; approves and annually reviews all policies; owns the annual risk assessment; approves gifts, hospitality and intermediary engagements above threshold; receives and assesses all speak-up reports; approves the internal audit plan.
  • ABAC Financial Controls — Managing Director with external accountants: verification of supplier bank accounts, review of expense and procurement documentation, and monthly reconciliation, with independent challenge from the company’s licensed external accountants on statutory accounts and tax filings.
  • ABAC Client & Content Compliance Focal Point (Deputy Compliance Reviewer): ensures creative, medical and event content complies with healthcare industry codes and client compliance policies; reviews proposed interactions with healthcare professionals before commitments are made; reviews any speak-up report involving the Managing Director.
  • ABAC Project, Third-Party & Records Focal Point: applies procurement and third-party requirements at project level — competitive quotations, due-diligence documentation, and flow-down of anti-bribery and confidentiality terms before a supplier starts work; maintains the gifts & hospitality register, compliance issue log, speak-up register and due-diligence files.
  • All employees and contractors: comply with the Code of Conduct and ABAC Policy, declare conflicts and gifts, and report suspected misconduct through the speak-up channels without fear of retaliation.
Anti-Bribery & Anti-Corruption Training

Mandatory on appointment · Annual refresher · Signed attendance record

All personnel complete anti-bribery and anti-corruption training on appointment and annually thereafter, aligned with AstraZeneca’s Expectations of Third Parties. Subcontractors and third-party agents must complete our briefing or evidence equivalent training before starting work.

  • Training within 30 days of joining or engagement, with an annual refresher; personnel serving a client engagement must hold current-year training before assignment.
  • Content covers applicable anti-bribery legislation, the prohibition on bribes, kickbacks and facilitation payments, gifts and hospitality thresholds, interactions with healthcare professionals and officials, conflicts of interest, accurate records, speak-up channels, and competition law.
  • Attendance is confirmed by signature and understanding by a question-and-answer review at the end of each session.
  • Training register, attendance records and materials are retained for at least five years and made available to clients or auditors on request.
  • Completion is reviewed annually; non-completion is logged and tracked as a compliance issue.
Prohibition of Facilitation Payments

Prohibited without exception · Preventive and detective controls

Facilitation payments — payments to a public official to secure or speed up a routine action they are already obliged to perform — are strictly prohibited in all circumstances, regardless of local custom, amount, or commercial consequence, and whether made directly or through any third party.

  • No cash payments to officials: the company holds no petty cash for such purposes; all disbursements are made by bank transfer to a verified account against an official receipt or tax invoice.
  • Every payment is approved by the Managing Director, with supporting records prepared and held separately, so no individual can both initiate and approve a payment without review.
  • Vague expense descriptions such as “processing fee” or “urgent handling” are rejected and escalated; suppliers and agents are contractually prohibited from making such payments on our behalf.
  • Monthly payment review, independent review by licensed external accountants, and annual internal audit provide detection.
  • Personnel are never required to place themselves at risk: where refusal would cause reasonable fear for personal safety, any payment made must be reported within 24 hours, recorded accurately, investigated, and disclosed to the affected client and authorities where required.
Fair Trading & Competition Law Compliance

Independent pricing · No bid rigging · Fair and balanced promotion

We compete on merit and comply with competition law, including Thailand’s Trade Competition Act B.E. 2560 (2017) and the Price of Goods and Services Act B.E. 2542 (1999), in every commercial dealing — quoting, tendering, purchasing, subcontracting, and promotion.

  • Prices and quotations are set independently on our own costs and commercial judgement; prices are never agreed, coordinated, or discussed with competitors.
  • No market sharing and no bid rigging: we never submit cover or courtesy bids, never agree who will win a tender, and never exchange bid terms with a competitor before award.
  • Promotional and comparative claims are accurate, substantiated, and fair, consistent with applicable healthcare industry codes.
  • Client and third-party confidential information is never used to gain market advantage or disclosed to competitors; tender information is never shared with another bidder.
  • Any competitor discussion touching price, bids, or client allocation must be objected to, exited, and reported the same day; competition law forms a mandatory part of annual training and is covered in the annual internal audit.
ABAC Risk Mitigation Measures — Summary of Policies, Controls and Assurance

Absolute prohibition · Three lines of control · Assess, prevent, detect, mitigate

Professor Healthcare Company Limited strictly prohibits the offering, promising, giving, soliciting, or accepting of anything of value intended to influence any action or decision, whether by our personnel or by any third party acting on our behalf, and whether the counterparty is a government official, a healthcare professional, a client representative, or a private party. This summary consolidates the policies, controls, training, monitoring, reporting and disciplinary measures that give effect to that position.

  • Policies: a register of the thirteen compliance policies bearing on bribery and corruption risk, from the ABAC Policy and Code of Conduct through to facilitation payments and fair trading, each signed and reviewed annually.
  • Assess: an annual ABAC risk assessment across clients, project types, suppliers, intermediaries, payment flows and geographies, recorded in a risk register with assigned owners and mitigating controls.
  • Prevent: Managing Director approval of every payment, supplier bank-account verification, no cash held for payments to officials, segregation of record-keeping from approval, gifts and hospitality thresholds with a maintained register, third-party due diligence with contractual flow-down, and mandatory training.
  • Detect: monthly management review of payments and expenses, independent review of statutory accounts and tax filings by our licensed external accountants, an annual internal audit programme, and a speak-up mechanism open to the public.
  • Mitigate: logged and confidential investigation, root-cause analysis, corrective actions tracked to closure, escalation to external advisors and authorities where required, and disclosure to any affected client.
  • Discipline: breach may result in disciplinary action up to termination of employment or contract and referral to authorities; for third parties, immediate suspension or termination of the engagement.
Top-Level Commitment Statement

Signed by the Managing Director · Zero tolerance · Tone from the top

A personal statement from our Managing Director, as sole authorised director, setting the tone from the top for the whole compliance framework. It is issued to every person on joining, repeated at each annual training session, and provided to subcontractors and agents before they begin work.

  • Zero tolerance toward bribery, corruption, fraud, facilitation payments and the facilitation of tax evasion — without exception, in every country where we work.
  • No one is authorised to pay a bribe, and no one will be criticised or disadvantaged for refusing to make an improper payment or for losing business as a result: any loss arising from acting honestly is a cost the company accepts.
  • Personal accountability held by the Managing Director as ABAC Compliance Owner, who approves every payment, every gift or hospitality item above threshold, and every engagement of an intermediary.
  • Procedures are deliberately proportionate to our size and risk — practical and genuinely followed rather than elaborate and ignored.
  • Speaking up is protected for anyone, including subcontractors, clients and the public; retaliation is itself a disciplinary offence.
Annual ABAC & Fraud Risk Assessment 2026

Ten assessed risks · Rated and owned · Reviewed annually

Our completed annual assessment of exposure to bribery, corruption, fraud and the facilitation of tax evasion, covering all business activities and all associated persons — employees, contractors, subcontractors, freelancers and agents. Each risk is rated High, Medium or Low against existing controls and assigned a named owner.

  • High: interactions with healthcare professionals (meals, honoraria, travel, sponsorship) and on-site event suppliers and freelancers engaged at short notice.
  • Medium: permits and government interactions, procurement and supplier selection, client billing and expense accuracy, branded gifts and premiums, and tender and competitive pitch conduct.
  • Low: facilitation of tax evasion by an associated person, personal data misuse in event registration, and political or charitable contributions.
  • Method, scope and conclusion are documented, with actions carried forward for the coming year and re-performance due by 1 September 2027.

Policy Documents

Signed full versions for download.

All eighteen documents are approved and signed by the Managing Director, effective 1 September 2026, with the next annual review due 1 September 2027. The framework is structured around the six principles of the UK Ministry of Justice guidance under section 7 of the Bribery Act 2010 and the equivalent principles in the UK Government guidance on the failure to prevent fraud offence under section 199 of the Economic Crime and Corporate Transparency Act 2023, applied proportionately to the size and risk profile of a small enterprise.

PHC-POL-001 · Version 2.0 · Effective 1 September 2026
Anti-Bribery & Anti-Corruption (ABAC) Policy
PDF ↓
PHC-POL-002 · Version 2.0 · Effective 1 September 2026
Code of Conduct
PDF ↓
PHC-POL-003 · Version 2.0 · Effective 1 September 2026
Hospitality & Gifts Policy
PDF ↓
PHC-POL-004 · Version 2.0 · Effective 1 September 2026
Expenses Policy & Procedures
PDF ↓
PHC-POL-005 · Version 2.0 · Effective 1 September 2026
Procurement & Buying Policy & Procedure
PDF ↓
PHC-POL-006 · Version 2.0 · Effective 1 September 2026
Compliance Programme, Risk Assessment & Monitoring
PDF ↓
PHC-POL-007 · Version 2.0 · Effective 1 September 2026
Whistleblowing & Speak-Up Policy
PDF ↓
PHC-POL-008 · Version 2.0 · Effective 1 September 2026
Management Oversight, Issue Resolution & Internal Audit
PDF ↓
PHC-POL-009 · Version 2.0 · Effective 1 September 2026
Data Protection & Privacy Policy
PDF ↓
PHC-POL-010 · Version 2.0 · Effective 1 September 2026
Access Control & Information Security Policy
PDF ↓
PHC-POL-011 · Version 2.0 · Effective 1 September 2026
Third-Party & Sub-processor Management Policy
PDF ↓
PHC-POL-012 · Version 1.0 · Effective 1 September 2026
ABAC Roles & Responsibilities
PDF ↓
PHC-POL-013 · Version 1.0 · Effective 1 September 2026
ABAC Training Policy & Record
PDF ↓
PHC-POL-014 · Version 1.0 · Effective 1 September 2026
Prohibition of Facilitation Payments
PDF ↓
PHC-POL-015 · Version 1.0 · Effective 1 September 2026
Fair Trading & Competition Law
PDF ↓
PHC-POL-016 · Version 1.0 · Effective 1 September 2026
ABAC Risk Mitigation Measures — Summary
PDF ↓
PHC-POL-017 · Version 1.0 · Effective 1 September 2026
Top-Level Commitment Statement
PDF ↓
PHC-RA-001 · Version 1.0 · Effective 1 September 2026
Annual ABAC & Fraud Risk Assessment 2026
PDF ↓

For questions regarding these policies or additional compliance evidence, contact sutiwas@proudtopresent.net · www.professorhealthcare.com