Compliance Risk Concepts
Client Login
compliance risk logo-2024

MNPI Policy Too Narrow? Common Compliance Gaps to Fix 

MNPI Policy Too Narrow? Common Compliance Gaps to Fix 

CRC
No Comments
July 2, 2026

There is a comfortable fiction embedded in how most registered investment advisers and broker-dealers think about material nonpublic information (MNPI). The fiction goes something like this: MNPI is a problem that arises when someone with inside knowledge trades the stock of the company they know something about. The SEC is the referee. The restricted list is the fence. If your clients trade equities and your compliance program covers equities, you're covered. That fiction is getting expensive. 

The enforcement landscape of the last two years has made one thing unmistakably clear: the information doesn't care what asset class you're in, the regulator doesn't have to be your regulator to make your life very difficult, and the trade doesn't have to be in the company you learned the secret about. The perimeter of MNPI risk has expanded in every direction simultaneously, and most compliance programs haven't moved with it. 

Shadow Trading: You Don't Have to Trade the Company You Know About 

Start with the most important doctrinal shift in insider trading law in a generation. In SEC v. Panuwat, a pharmaceutical executive at Medivation learned his company was about to be acquired. Rather than trading Medivation's own securities, he purchased short-term, out-of-the-money stock options in Incyte Corporation, a comparable mid-cap oncology company, within minutes of learning the confidential deal information. The SEC called this "shadow trading," and a jury found him liable after an eight-day trial in April 2024, with the Enforcement Division declaring it "insider trading, pure and simple". 

The SEC has now filed two enforcement actions under the shadow trading theory, with the second case, a settled judgment against Arista Networks' former chairman and CEO Andreas Bechtolsheim, demonstrating that shadow trading involves using MNPI learned from one company to trade in a different company whose share price is predictably influenced by the disclosure of that MNPI.  

Think carefully about what this means for your firm. If an analyst at a healthcare-focused RIA learns MNPI about a drug approval at a portfolio company, your restricted list blocks them from trading that company's stock. Does it block them from trading a competitor, a supplier, or an ETF with heavy sector concentration? Almost certainly not, because most policies were never written with that scenario in mind. 

The SEC has argued that traditional principles of agency law suffice to establish liability even without an applicable insider trading policy provision, because confidential information is traditionally for the exclusive benefit of the corporation, and use of that information for personal benefit by an employee could suffice for a Section 10(b) claim. The absence of a policy covering shadow trading doesn't protect you. It may make things worse.  

It is worth noting the current political temperature: Commissioners Hester Peirce and Mark Uyeda were highly critical of the shadow trading theory and issued dissents when staff recommended cases for prosecution under that theory, and with Chairman Atkins now holding the Commission's majority, the shadow trading theory may be put on ice for the time being. But "on ice" is not "dead." The Panuwat verdict stands. A future commission can revive it. And critically, a plaintiff's bar that understands the theory does not need the SEC to act first. Build the policy now.  

Credit Markets: When MNPI Creates Liability, No Security Required 

A quieter but equally important expansion has been underway in credit markets. Although insider trading investigations have typically involved equity securities, in 2024 the SEC scrutinized ad hoc creditor committee participants and took enforcement action against distressed debt managers relating to MNPI.  

The most instructive case involved collateralized loan obligations. In August 2024, the SEC charged Sound Point Capital Management - a New York-based CLO manager - with failing to maintain adequate policies to prevent MNPI misuse, resulting in a $1.8 million civil penalty. The specific facts are worth understanding: Sound Point sold two CLO equity tranches while in possession of MNPI about an underlying borrower obtained through its participation in an ad hoc lender group. When that MNPI was publicly released the following day, the value of the loans in those tranches dropped by over 50%. 

Here is the structural puzzle that makes this so treacherous. The underlying loans themselves would likely not be securities under the Second Circuit's recent Kirschner decision, which held that syndicated loans are not securities under the Securities Act and Exchange Act. Nevertheless, confidential information about a loan or a borrower can be MNPI relating to another security. The loan is not the security, the CLO tranche is. The information travels from one to the other, and the SEC's jurisdiction follows.  

The compliance gap that got Sound Point in trouble is one many firms share: the RIA had an insider trading policy that prevented trading in the securities of a company while in possession of MNPI about that company, but the policy contained no prohibitions on trading a CLO tranche while in possession of MNPI about the underlying loans in that CLO. The gap between what the policy said and what the business did was exactly where liability lived. Sound Point did not adopt written policies for MNPI about an underlying borrower obtained through its participation in an ad hoc lender group. When that MNPI was publicly released the following day, the value of the loans in those tranches dropped by over 50%. 

In a second enforcement action in September 2024, the SEC charged a registered investment adviser for failing to establish policies that took into account the special circumstances presented by potential MNPI obtained through participation in ad hoc creditors' committees.  

The SEC Enforcement Division has been direct about the lesson for multi-strategy firms: "Fund managers, including those with multiple business lines or strategies, must consider how they may come into possession of material nonpublic information and then adopt and implement reasonable policies and procedures around those risks." Any RIA with exposure to private credit, distressed debt, creditor committees, or CLO structures should treat that statement as directed at them. 

For broader context on what the SEC's Division of Examinations expects from RIA compliance programs in this area, the April 2022 MNPI Risk Alert remains the authoritative reference, and its identification of MNPI deficiencies as among the most commonly observed findings in adviser examinations should give every CCO pause. The full text of the risk alert details specific failures the staff has repeatedly seen, including inadequate controls around alternative data, expert networks, and "value-add investors" who may themselves hold MNPI. 

Worth noting: Section 204A of the Investment Advisers Act requires all investment advisers, registered or not, to establish, maintain, and enforce written policies reasonably designed to prevent MNPI misuse. The SEC has made clear it is not sufficient for RIAs to have in place a general insider trading policy that blanketly prohibits trading on MNPI, even when the firm implementing the policy is organized across multiple lines of business.  

Prediction Markets: A New Asset Class, an Old Problem, and a Regulator Paying Attention 

Now consider a category that most RIA and BD compliance programs don't mention at all, because until recently, there was no reason to: prediction markets. 

On March 31, 2026, CFTC Enforcement Director David Miller delivered his first public remarks as director at NYU Law School and made his priority unmistakable: insider trading in prediction markets is the CFTC Division of Enforcement's top focus. He called the idea that insider trading is "permissible" in prediction markets a "myth,” and announced that the Commission will be "policing the illegal use of government information in the prediction markets." That is not a subtle signal. 

The CFTC has asserted primary regulatory authority over prediction markets, identifying event contracts as "swaps" or "derivatives" that fall within its exclusive jurisdiction under the Commodity Exchange Act. The CFTC prohibits trading on MNPI in derivatives markets, including futures and swaps, under CEA Section 6(c)(1) and Regulation 180.1. And as the CFTC's March 2026 Staff Advisory 26-08 makes explicit, registered prediction market venues like Kalshi and Polymarket US are designated contract markets, subject to full CFTC oversight. The Commission has also published an enforcement advisory on this specific topic, confirming it "has full authority to police illegal trading practices occurring on any DCM, including those related to prediction markets."  

Now consider what prediction markets actually are: contracts whose payoff is determined by whether a specific event occurs. Will this company announce a merger? Will this drug receive FDA approval? Will this earnings figure hit a certain threshold? For someone inside a company, the ability to bet on outcomes they already know is extraordinarily tempting, and increasingly dangerous. 

Most corporate insider trading policies are drafted to cover "securities," while many prediction market contracts may not fall, or be perceived to fall, within the definition of a "security." An employee who understands that stock trading is prohibited while in possession of MNPI may mistakenly believe that betting on whether the company will announce a merger, release a product, receive regulatory clearance, or hit an earnings milestone is outside the policy. That belief is wrong and increasingly costly.  

The enforcement implications extend even to information that wouldn't ordinarily be classified as MNPI. The DOJ and CFTC cases demonstrate that a wide range of information -- including corporate data such as internal metrics as well as government or regulatory information -- may be material to derivatives pricing if it bears on the likelihood of an event outcome. In one matter, underlying data that would not typically be viewed as MNPI for purposes of trading in the relevant company's securities became economically material when tied to the pricing of event-based contracts. The proliferation of event contracts has dramatically expanded the boundaries of potential MNPI.  

Comply's recent compliance guidance for RIAs on prediction markets frames the structural problem clearly: employees with access to MNPI obtained through their advisory role could use that information to trade on prediction market platforms in ways that mirror insider trading even where the instruments are not technically securities. The CFTC's parallel provisions (CEA Section 6(c)(1) and Regulation 180.1) apply regardless of whether the SEC's framework does. 

An analyst, for example, might use nonpublic information to position fund or client trades ahead of public disclosure, potentially without the client's knowledge. In that situation, the individual employee faces liability. Regulators may also scrutinize whether the firm's MNPI personal trading, code-of-ethics, and supervisory controls were reasonably designed and enforced to address misuse of confidential information through commodity interests.  

The Cross-Regulator Problem 

Here is where the compliance picture gets structurally complicated in a way that most policies don't address. 

Your firm is regulated by the SEC. Your MNPI policy was designed with the SEC's rules in mind. But prediction markets are primarily regulated by the CFTC. Shadow trading was pursued by the SEC. Credit market violations implicate both Section 204A of the Advisers Act and CFTC provisions depending on the instrument. A former Federal Reserve examiner was charged with insider trading for using confidential supervisory information from his position to execute 69 trades in seven publicly traded financial institutions, generating approximately $771,678 in illicit profits, demonstrating that MNPI can originate in regulatory employment entirely outside the securities industry.  

The information that creates liability doesn't originate in one regulatory silo and stay there. A person at an SEC-regulated RIA can receive MNPI, use it to trade a CFTC-regulated instrument, and face enforcement from either agency, or both, as recent DOJ and CFTC joint actions have demonstrated. The question "does my regulator cover that?" is the wrong question. The right question is whether the conduct is prohibited, by anyone, anywhere. 

The SEC's information barriers guidance, while focused on broker-dealers, articulates the broader principle: firms must think about how information gathered across business lines can constitute MNPI regardless of where in the organization it sits. FINRA's own rules, including Rules 20102020, and 5270, impose parallel obligations on broker-dealers that exist independently of what the SEC oversees. 

How to Update Your MNPI Policy: 5 Gaps to Close 

This is not an argument that compliance is impossible or that the rules are unfair. It's an argument that the rules have grown to match the complexity of modern markets, and policies need to catch up. Sometimes a second set of eyes makes all the difference, especially when those eyes have sat in the CCO chair; CRC works with firms on exactly this. A few specific gaps to close: 

Shadow trading coverage. Your personal trading policy should explicitly address trading in economically correlated instruments -- competitors, suppliers, customers, sector ETFs -- on the basis of MNPI about a different entity. The policy doesn't need to prohibit all such trading, but it needs to name the risk and require pre-clearance or disclosure when the correlation is meaningful. The SEC's original Panuwat complaint is instructive about the breadth of language regulators expect insider trading policies to include, specifically coverage extending to "significant collaborators, customers, partners, suppliers, or competitors." 

Cross-asset information mapping. If your firm participates in creditor committees, lender groups, or private credit structures, you need a written map of how information obtained in those contexts could be material to the securities you trade. The SEC has identified these situations as involving heightened MNPI risk, emphasizing the need for clear written procedures to handle MNPI and mitigate risks of leakage or inadvertent receipt. The SEC is not impressed by policies that address the trading but not the information flows that precede it.  

Prediction market prohibitions. Add them. Explicitly. Because event contracts aren't classified as securities, they may fall outside the scope of policies that prohibit the misuse of MNPI solely in connection with securities trading. Firms should consider expanding insider trading policies to cover the use of MNPI in connection with event contracts and other non-securities instruments, explicitly referencing prediction markets and other trading platforms. Firms should also consider whether their codes of conduct, which typically apply firmwide rather than only to designated access persons, can serve as a backstop prohibition on using confidential information regardless of the market or instrument used to monetize it.  

Multi-regulator awareness. Your policy should acknowledge that MNPI obligations are not coterminous with SEC jurisdiction. Employees should understand that trading in futures, swaps, event contracts, or other derivatives on the basis of nonpublic information may be prohibited by the CFTC, the DOJ, or other regulators entirely regardless of what your SEC-focused policy says. The CFTC's CEA Section 6(c)(1) and Regulation 180.1 create parallel insider trading prohibitions that your employees may have never encountered in training. 

Training that reflects reality. The annual MNPI training that walks through the classic insider trading scenario -- executive trades his own company's stock on earnings news-- is insufficient. Add the shadow trading hypothetical. Add the "I placed a prediction market bet on our drug trial results" hypothetical. Add the "I sold CLO tranches after joining the creditor committee" hypothetical. The SEC's Division of Examinations has flagged training gaps as a recurring deficiency, particularly around alternative data, expert networks, and access persons who may not fully understand the scope of their obligations. 

The Core Point  

The architecture of MNPI risk has always been built around a simple insight: people with information advantages will use them, markets depend on that not happening in unfair ways, and regulators will punish it when they find it. What has changed is the surface area. The assets across which information advantages can be exploited have multiplied. The regulators watching those assets have multiplied. The theories of liability have multiplied. 

Your MNPI policy, if it was written five years ago and updated only at the margins, is probably protecting against the last enforcement cycle, not this one. That's a problem you can fix. The firms that are going to have a bad time are the ones that learn the new perimeter the hard way: through an examination finding, a Wells notice, or a jury verdict. 

The map is not necessarily the territory, and it is time to update the map.  

RECENT POSTS

Regulatory Update
Crc-Oyster | 2026 Midyear Regulatory Landscape Check-in...

Where We Have Been, Where the Signals Point, and What to Do Before Year-End The […]

Read More
Regulatory Update
FinCEN Issues Advisory on Financial Integrity; Its...

The recent FinCEN advisory directing financial institutions to detect and report suspicious activity linked to […]

Read More
CRC-Oyster Roundtable
When the Federal Safety Net Loosens, State...

The CRC-Oyster Roundtable on State Securities Regulatory Priorities for Broker-Dealers and Investment Advisers There's a […]

Read More

CRC NEWSLETTER

Stay updated with all latest updates,upcoming events & much more.

Subscribe NowSupport

Recent Blogs

Stay informed with our latest articles.
Regulatory Update
Crc-Oyster | 2026 Midyear Regulatory Landscape Check-in...

Where We Have Been, Where the Signals Point, and What to Do Before Year-End The […]

Read More
Regulatory Update
FinCEN Issues Advisory on Financial Integrity; Its...

The recent FinCEN advisory directing financial institutions to detect and report suspicious activity linked to […]

Read More
CRC-Oyster Roundtable
When the Federal Safety Net Loosens, State...

The CRC-Oyster Roundtable on State Securities Regulatory Priorities for Broker-Dealers and Investment Advisers There's a […]

Read More
Copyright Compliance Risk Concepts | All Rights Reserved © 2023 | Privacy Policy
magnifier