Supplier Code of Conduct
Every supplier that works with MRG must meet the standards in this Code. Suppliers are responsible for making sure everyone working on their behalf follows it.
1. Introduction
MRG provides IT consulting and systems integration services, often to clients in regulated industries such as healthcare, so our suppliers' conduct reflects directly on us and on our clients.
This Code applies to every company, staffing partner, contractor and consultant that supplies goods or services to MRG ("Suppliers"), and to their owners, employees, subcontractors and agents.
This Code supplements, and does not replace, the terms of any agreement between MRG and a Supplier. Where an agreement sets a stricter standard, the agreement controls. Suppliers must also follow any additional code of conduct or policy of an MRG client that applies to their work.
2. Compliance with laws
Suppliers must comply with all laws and regulations that apply to their business and to the work they perform for MRG, in every country, state and locality where they operate. If this Code and the law differ, Suppliers must follow whichever standard is stricter.
3. Anti-bribery and anti-corruption
MRG has zero tolerance for bribery and corruption. Suppliers must comply with all anti-corruption laws, including the U.S. Foreign Corrupt Practices Act (FCPA), the U.S. federal Anti-Kickback Statute, the UK Bribery Act 2010 and applicable state commercial bribery laws.
Suppliers must never, directly or through anyone else:
- Offer, promise, give or accept money or anything of value to improperly influence a decision, win or keep business, or gain an unfair advantage.
- Make payments of any kind to government officials to obtain or speed up any action, including so-called "facilitation" or "expediting" payments. Government officials include employees of public hospitals, public universities and other state-owned or state-controlled organizations.
- Pay or offer kickbacks, rebates or a share of fees to anyone at MRG or at an MRG client.
- Offer or pay anything of value to induce the referral of business that may be paid for by a government healthcare program.
4. Gifts, entertainment and conflicts of interest
Business decisions at MRG are made on merit alone. Suppliers may offer MRG or MRG client employees only modest business courtesies that:
- Are worth no more than US $100 in total per person per calendar year.
- Are never cash or cash equivalents, such as gift cards.
- Are lawful and allowed by the recipient's own employer policies.
- Are not given while a decision affecting the Supplier is pending, such as a bid, contract award or renewal.
Suppliers must disclose to MRG in writing any actual or potential conflict of interest. This includes any case where an MRG or MRG client employee, or a member of their immediate family, owns part of, works for or is paid by the Supplier, and any case where a government official is an owner, officer or employee of the Supplier.
5. Fair competition, sanctions and trade controls
Suppliers must compete fairly and comply with antitrust and competition laws. They must not fix prices, rig bids, divide customers or markets, or share competitively sensitive information with competitors.
Suppliers must comply with all applicable economic sanctions and export control laws, including those administered by the U.S. Treasury Department's Office of Foreign Assets Control (OFAC). Suppliers must not be, or be owned or controlled by, any person on the OFAC Specially Designated Nationals List or another U.S. government restricted-party list. They must tell MRG immediately if their status changes.
Suppliers must not trade in the securities of MRG's clients based on non-public information they learn through their work.
6. Labor and human rights
Suppliers must treat workers with dignity and respect and comply with all applicable labor and employment laws. In particular, Suppliers must:
- Not use forced, bonded, indentured or involuntary prison labor, and not engage in or support human trafficking in any form.
- Not use child labor or employ anyone below the legal minimum working age.
- Never require workers to pay recruitment fees or surrender identity documents as a condition of work.
- Pay at least the legally required wages and benefits, including overtime, and keep working hours within legal limits.
- Provide a workplace free from harassment, discrimination and retaliation, and make employment decisions based on qualifications and merit.
- Verify that every worker assigned to MRG work is legally authorized to work in the relevant country.
- Respect workers' lawful rights to associate freely.
7. Health, safety and environment
Suppliers must provide a safe and healthy work environment and comply with all applicable occupational health and safety laws. Workers placed at MRG or client sites must follow those sites' safety and security rules.
Suppliers must comply with applicable environmental laws and are encouraged to reduce waste, energy use and their environmental footprint. Suppliers handling IT equipment must dispose of it responsibly and securely wipe any data it holds.
8. Confidentiality, data privacy and information security
Suppliers often have access to confidential information and personal data belonging to MRG, our clients and their customers or patients. Suppliers must:
- Use confidential information only to perform their work for MRG and never disclose it without authorization.
- Comply with all applicable data protection and privacy laws, including HIPAA where protected health information is involved.
- Maintain reasonable administrative, technical and physical safeguards, including access controls and encryption for personal data in transit.
- Notify MRG within three (3) days of discovering any actual or suspected security breach involving MRG or client data.
- Return or securely destroy MRG and client data when the work ends or when MRG asks.
- Not use MRG's name, logo or client names in marketing without MRG's written permission.
9. Healthcare program compliance
Many of MRG's clients operate in healthcare, which carries additional legal requirements. Suppliers must not employ, engage or assign to MRG work any person or entity that is excluded, debarred or suspended from federal healthcare or procurement programs. This includes anyone listed on the HHS Office of Inspector General's List of Excluded Individuals/Entities (LEIE) or the System for Award Management (SAM.gov).
Suppliers must screen workers against these lists before assigning them to MRG work and at least monthly after that. They must notify MRG immediately if a match is found.
10. Accurate records, audits and cooperation
Suppliers must keep complete and accurate books and records of all work, invoices, timecards, expenses and payments related to MRG. Suppliers must never create false or misleading entries, keep off-book accounts, or submit inflated invoices, timecards or expense claims. Records must be kept for at least six (6) years.
MRG, or an auditor it appoints, may review a Supplier's records and practices on reasonable notice to confirm compliance with this Code. Suppliers must cooperate fully with any such review and with any related internal or government investigation.
11. Subcontractors
Suppliers may not subcontract any MRG work without MRG's prior written approval. Suppliers must hold approved subcontractors to standards at least as strict as this Code and remain responsible for their conduct.
12. Reporting concerns and non-retaliation
Suppliers and their workers should report any suspected violation of this Code, any request for an improper payment, or any government investigation involving bribery, fraud or healthcare program integrity. Suppliers must report these matters to MRG within five (5) business days of becoming aware of them.
Reports can be sent to compliance@metaresourcesgroup.com or by mail to Meta Resources Group, Inc., Attn: Compliance, 50 Carlton Road, Orangeburg, NY 10962. Reports may be made anonymously where the law allows, and MRG will treat them as confidentially as possible.
MRG prohibits retaliation against anyone who raises a concern in good faith, and Suppliers must not retaliate against their own workers for doing so.
13. Compliance, consequences and acknowledgment
Suppliers must make sure their workers assigned to MRG are aware of this Code and trained on it as appropriate. MRG may ask Suppliers to confirm their compliance in writing, typically once a year.
Violating this Code may lead to corrective action, removal of individual workers from MRG assignments, suspension of work, or termination of the business relationship, in addition to any remedies available under the Supplier's agreement with MRG or the law.
MRG may update this Code from time to time. The current version is always available on MRG's website. Questions about this Code can be directed to compliance@metaresourcesgroup.com.