Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Insider Trading Controls: Build a Program That Passes SEC ScrutinyRegulatory Compliance
6 min readFor Compliance Officers

Insider Trading Controls: Build a Program That Passes SEC Scrutiny

The SEC recently charged two former investment bankers, including a former Bank of America employee, with insider trading related to the 2022 acquisition of South Jersey Industries. These enforcement actions are not slowing down. Your compliance program must detect material non-public information (MNPI) misuse before regulators do, or you'll be explaining failures to the board and possibly the SEC.

This guide walks you through building an insider trading compliance program that creates defensible controls, not just policy documents.

The Problem: Why This Matters Now

Insider trading enforcement targets individuals, but regulatory scrutiny falls on the institution's compliance structure. When the SEC investigates, they'll ask: Did you have adequate controls? Did you monitor suspicious trading? Did you enforce restrictions?

If your answer is "we have a policy employees sign annually," you don't have a program. You have documentation that proves you knew about the risk but didn't control it.

Financial institutions face particular exposure because employees routinely access MNPI across multiple deals. A single lapse creates legal liability, reputational damage, and regulatory consent orders that reshape your entire compliance function.

What You Need Before Starting

Before you build controls, confirm you have:

Authority and resources:

  • Executive sponsorship from the Chief Compliance Officer or General Counsel
  • Budget for monitoring technology (expect $50K-$500K annually depending on firm size)
  • Dedicated compliance staff with securities law expertise
  • Access to HR systems, trading platforms, and deal pipeline data

Baseline documentation:

  • Current insider trading policy (even if inadequate)
  • List of all employees with regular MNPI access
  • Inventory of systems where MNPI is stored or transmitted
  • Trading account information for covered employees

Technical access:

  • API or data feed from brokerage platforms where employees trade
  • Integration capability with your deal management system
  • Ability to flag restricted securities in real-time

If you lack executive buy-in, start there. Frame the business case around regulatory risk, not theoretical compliance. Reference recent SEC enforcement actions and the institutional costs of inadequate controls.

Step-by-Step Implementation

Phase 1: Define Your Restricted List Process

Your restricted list identifies securities that employees cannot trade due to MNPI exposure. This isn't a static document.

Week 1-2: Establish list governance

Create a Restricted List Committee with representatives from:

  • Compliance (chair)
  • Investment banking or deal teams
  • Legal
  • Trading desk supervisors

Document the committee's authority to add securities, review frequency (weekly minimum), and escalation procedures.

Week 2-3: Build the technical infrastructure

Configure your system to:

  • Automatically block trades in restricted securities at the brokerage level (pre-clearance rejection)
  • Flag attempts to trade restricted securities for compliance review
  • Generate alerts when employees query information about restricted securities in internal systems

If you don't have a GRC platform with securities monitoring, evaluate vendors like Compliance.ai, ComplyAdvantage, or specialized insider trading surveillance tools. At minimum, you need automated blocking, not manual review of every trade.

Week 3-4: Define addition and removal criteria

Document specific triggers for adding securities:

  • Firm is engaged as advisor on M&A, capital raise, or restructuring
  • Employee team begins due diligence
  • Confidentiality agreement is signed with potential counterparty

Set removal rules:

  • Information becomes public (press release, SEC filing)
  • Deal is abandoned and confidentiality obligations expire
  • Minimum waiting period after public disclosure (typically 2 business days)

Phase 2: Implement Pre-Clearance Controls

Pre-clearance requires employees to request approval before trading any security. This control catches conflicts the restricted list might miss.

Week 4-5: Configure the pre-clearance workflow

Build a system (or procure software) where employees submit:

  • Security identifier (ticker, CUSIP)
  • Transaction type (buy, sell, option exercise)
  • Account information
  • Attestation that they don't possess MNPI

Set approval requirements:

  • Automatic approval for non-restricted securities with no red flags
  • Compliance review required if employee worked on related matters in past 6 months
  • Supervisor approval for all trades by investment banking personnel
  • Time limit on approvals (typically 3 business days; employee must trade within that window or re-request)

Week 5-6: Define your blackout periods

Establish firm-wide blackout windows:

  • Earnings announcement periods (typically 15 days before through 2 days after)
  • Material event blackouts (deal closings, major contract announcements)
  • Year-end financial close periods

Configure your system to automatically reject pre-clearance requests during blackouts for affected securities.

Phase 3: Build Surveillance and Monitoring

Automated surveillance detects patterns that suggest MNPI misuse.

Week 6-8: Deploy trade surveillance

Configure alerts for:

  • Trading in restricted securities (should be blocked, but flag system bypasses)
  • Trading immediately before material announcements (within 5 days)
  • Unusual trading volume or patterns (employee typically trades monthly but suddenly executes 10 transactions in a week)
  • Trading in securities of clients or counterparties
  • Options trading in any security where employee has deal exposure

Set alert thresholds based on your risk appetite. High-risk roles (M&A bankers, research analysts) should trigger alerts at lower thresholds than administrative staff.

Week 8-9: Implement personal account reporting

Require covered employees to:

  • Report all brokerage accounts within 10 days of hire
  • Provide quarterly or monthly statements (automated feed is better than manual submission)
  • Disclose accounts held by immediate family members
  • Report new accounts within 30 days

Configure your system to reconcile reported accounts against trading activity. Flag discrepancies where trades appear that weren't pre-cleared.

Phase 4: Training and Attestation

Controls fail if employees don't understand them.

Week 9-10: Develop role-based training

Create separate training modules for:

  • Investment banking and deal teams: Detailed MNPI identification, restricted list procedures, blackout periods
  • Research analysts: Regulation FD implications, publication blackouts, interaction restrictions
  • Trading desk and portfolio managers: Front-running prohibitions, information barriers
  • Administrative and support staff: Basic policy awareness, reporting obligations

Include scenario-based questions. "You overhear a conversation about an upcoming acquisition. What do you do?" Generic multiple-choice tests don't change behavior.

Week 10-11: Deploy annual attestation

Require employees to certify annually that they:

  • Read and understand the insider trading policy
  • Reported all trading accounts
  • Complied with pre-clearance requirements
  • Don't currently possess MNPI about any publicly traded company outside approved deal contexts

Track attestation completion rates. Non-compliance with attestation is itself a red flag.

Validation: How to Verify It Works

Don't wait for an SEC investigation to test your controls.

Monthly validation checks:

Run these reports and review with the Restricted List Committee:

  • Pre-clearance requests denied (confirm denials were appropriate)
  • Trades executed without pre-clearance (investigate each instance)
  • Surveillance alerts generated and disposition (closed as false positive vs. escalated)
  • Restricted list additions and removals (verify proper authorization)
  • Employees who haven't attested or reported accounts (follow up within 48 hours)

Quarterly control testing:

Test control effectiveness:

  • Select 10 random trades by covered employees; verify pre-clearance documentation exists
  • Select 5 securities added to restricted list; confirm addition occurred before MNPI was accessible
  • Review 3 surveillance alerts; validate compliance investigated and documented findings
  • Audit information barriers; confirm deal team members can't access unrelated client data

Document all testing. If a control fails, remediate immediately and document the corrective action.

Annual independent review:

Engage internal audit or external counsel to assess:

  • Policy completeness compared to SEC guidance and industry standards
  • Control design adequacy
  • Operating effectiveness based on testing samples
  • Technology configuration and access controls
  • Training completion and comprehension

This review creates defensible documentation if regulators question your program.

Maintenance: Ongoing Tasks

Compliance programs decay without active maintenance.

Daily:

  • Review surveillance alerts (assign to compliance analyst)
  • Process pre-clearance requests (set SLA: 4 hours for standard requests)

Weekly:

  • Restricted List Committee meeting
  • Review new deals or engagements that trigger additions
  • Remove securities where information is now public

Monthly:

  • Reconcile employee trading accounts against reported accounts
  • Review pre-clearance denial trends (are employees repeatedly requesting restricted securities? Retrain them.)
  • Update surveillance alert thresholds based on false positive rates

Quarterly:

  • Control testing and documentation
  • Review policy against regulatory updates
  • Assess technology performance and user adoption

Annually:

  • Refresh training content
  • Deploy attestation campaign
  • Independent program assessment
  • Report to board or audit committee on program effectiveness metrics

After any enforcement action (internal or external):

  • Conduct root cause analysis
  • Identify control gaps
  • Implement remediation
  • Document lessons learned

When Controls Aren't Enough

Even strong programs face challenges. If you detect a potential violation:

  1. Immediately restrict the employee's trading access
  2. Preserve all relevant communications and trading records
  3. Engage legal counsel before interviewing the employee
  4. Assess whether self-reporting to the SEC is appropriate (discuss with counsel)
  5. Document your investigation process and findings

The SEC evaluates cooperation when determining penalties. A robust program that detected and reported a violation demonstrates good faith. No program that ignored red flags gets that credit.

Your insider trading compliance program isn't a checkbox. It's a continuous control structure that protects your institution from regulatory exposure and reputational damage. Build it with the assumption that the SEC will review it, because eventually, they might.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like