Preventing Insider Trading: 5 Essential Controls for Companies

Preventing Insider Trading

Preventing insider trading does not start when someone decides to buy or sell a security. It begins much earlier—when potentially material information is created, discussed, recorded, or shared within a company.

An unannounced acquisition, a change of control, financial results, the loss of a major contract, or a corporate restructuring can circulate through various departments before reaching the market. Along this path, the information may be accessed by executives, employees, consultants, auditors, financial advisors, and vendors.

The greater the number of people and systems involved, the greater the need for governance.

This concern gains even more relevance with the modernization of supervision in the Brazilian capital market. In July 2026, the Supreme Federal Court approved the emergency restructuring plan for the Securities and Exchange Commission of Brazil (CVM). Among the announced measures are infrastructure technology upgrades, expanded use of artificial intelligence and data analytics tools, and strengthened cooperation between public authorities.

The technical document prepared by the CVM outlines a market abuse detection program based on trading data, pattern recognition, machine learning, network analysis, and integration with registration and financial data. The scope explicitly includes insider trading.

This does not mean that atypical trading behavior will automatically be deemed unlawful. A technology alert is a starting point for analysis, not a final conclusion. However, data-driven supervision makes it increasingly vital for a company to demonstrate who accessed specific information, when it occurred, what restrictions were in place, and how individuals were instructed.

In this scenario, generic policies and informal controls are insufficient. Prevention relies on five controls connected to the organization’s daily routine.

Before the Controls: What is Insider Trading?

CVM Resolution 44 prohibits the use of material, non-public information by anyone who has gained access to it in order to obtain an advantage for themselves or a third party through securities trading.

The phrase “anyone” is key. Risk is not limited to directors, board members, or controlling shareholders. Depending on the circumstances, it may involve employees, consultants, auditors, advisors, suppliers, and individuals who received the information through a commercial, professional, or trust relationship.

The regulation also establishes rebuttable presumptions for certain scenarios. Among them, it is presumed that a person who traded while in possession of material, non-public information made use of that information. However, any analysis must consider all elements of the case.

Beyond administrative enforcement, Article 27-D of Law No. 6,385/1976 criminalizes the misuse of privileged information. The statute also covers the tipping of confidential information regarding a material fact by anyone who obtained access due to their position, title, or professional, commercial, or trust relationship.

Therefore, preventing insider trading means controlling the entire lifecycle of material information—not just banning trades during specific windows.

1. Map and Classify Potentially Material Information

The first control consists of identifying where sensitive information originates, who participates in its production, and through which channels it travels.

Financial results are the most widely known example, but they are not the sole source of risk. M&A transactions, changes in control, restructurings, judicial recovery filings, capital raises, material contracts, IT security incidents, and strategic decisions may also demand special handling.

This mapping must cover the full lifecycle of the information:

  • where it was generated;

  • when it became potentially material;

  • which departments participated in its review;

  • which systems stored the documents;

  • which third parties were granted access;

  • when public disclosure occurred.

A common mistake is classifying information as sensitive only when a transaction is nearly finalized. In many cases, risk emerges during preliminary studies or analyses.

A company does not need to treat every document as privileged information—that would make controls unworkable. The goal is to establish clear criteria for recognizing information that could significantly influence investor decisions and apply protection proportional to the risk.

The question to ask: Can your company identify when sensitive information arose and reconstruct its path up to public disclosure?

2. Restrict Access and Maintain Traceability

Once information is identified, you must control who actually needs access to it.

The principle is straightforward: access is granted on a strict need-to-know basis, not out of convenience, hierarchy, or general participation in a department.

Overly broad distribution lists, informal messaging groups, unrestricted folders, and outdated user permissions that were never revoked unnecessarily increase exposure.

A solid control framework must make it possible to identify:

  • who received access;

  • for what reason;

  • on what date;

  • to which documents or systems;

  • when access was modified or revoked.

Strategic projects may also utilize project-specific access lists, codenames, and segregated document environments. Meetings should be limited to essential participants, and meeting materials must be treated according to their confidentiality level.

Technology helps log access, edits, and sharing activities. However, it does not replace personal responsibility. An authorized employee can still create exposure by discussing a project in an inappropriate setting, forwarding a document to the wrong contact, or using unapproved tools.

Therefore, traceability and awareness must work together.

The organization must know exactly who had access to each sensitive project and be able to justify that access.

3. Make the Trading Policy Actionable in Daily Routines

A trading policy must not exist merely to check a compliance box; it must guide concrete decisions.

The document should explain in clear language:

  • who is subject to the rules;

  • which assets and transactions are covered;

  • when pre-clearance is required;

  • how blackout periods work;

  • how to declare accounts, holdings, or conflicts;

  • which channel to consult when in doubt;

  • how exceptions are handled.

CVM Resolution 44 imposes trading bans on certain covered persons during the 15 days preceding the disclosure of quarterly financial information and annual financial statements, subject to the conditions outlined in the rule.

This regular blackout window does not eliminate other restrictions. An individual possessing material non-public information should not interpret the absence of a calendar block as automatic authorization to trade.

Extraordinary transactions may also require specific trading bans that must be communicated swiftly to affected individuals. Approvals, denials, inquiries, and exceptions must be documented.

Another key point is preventing the policy from relying on memory alone. Automated alerts, updated calendars, and pre-clearance workflows help turn rules into usable controls.

Can employees quickly determine whether a restriction exists and who to consult before trading?

4. Include Third Parties and Related Persons in Governance

Strategic information does not circulate exclusively among internal employees.

Law firms, audit firms, investment banks, consultancies, PR agencies, financial advisors, and technology vendors may receive access to confidential projects. These third parties must be factored into the risk assessment.

Contracts and Non-Disclosure Agreements (NDAs) are important, but they are not enough on their own. Companies must evaluate what information will be shared, who will access it, how documents will be protected, and when permissions will be terminated.

Internal teams must also understand that informally passing along information can create exposure even if the employee does not execute any trade themselves.

Consider a hypothetical example: an employee mentions at home that the company is about to announce an acquisition. A close relation uses that information to trade securities. The risk does not vanish simply because the order was placed by someone else.

Precaution must extend to casual conversations, messaging apps, personal devices, public spaces, and professional or personal relationships that could facilitate the misuse or tipping of information.

This does not mean intrusively monitoring employees’ private lives. It means clearly explaining confidentiality boundaries, sharing risks, and regulatory obligations.

Verify whether third parties and temporary insiders receive guidance aligned with the sensitivity of the information.

5. Deliver Role-Based Training and Test Practical Decision-Making

The fifth control connects all the previous ones: training.

A well-written policy loses effectiveness when people fail to recognize a risk scenario. Likewise, a pre-clearance system fails if employees do not know when to use it.

Training should stem from the real dilemmas faced by each audience group. Executive Leadership, Investor Relations, Legal, Compliance, Finance, M&A, IT, and external vendors face distinct exposures.

Scenarios to address include:

  • unexpected receipt of material information;

  • personal trading during sensitive windows;

  • doubts about a specific account or asset class;

  • sharing project documents with external consultants;

  • informal discussions regarding confidential projects;

  • loss of confidentiality or sending files to the wrong recipient;

  • identifying potential conflicts of interest;

  • suspicions of atypical trading.

The goal is not to turn every employee into a capital markets legal expert. It is to empower them to recognize red flags, pause an inappropriate decision, and seek guidance before taking action.

The organization must also maintain auditable records of the learning journey, including invited audiences, content covered, attendance logs, assessments, and post-training refreshers. Certificates and reports are useful, but they should not be confused with isolated proof of effectiveness.

An evaluation based solely on conceptual questions may show memorization. Simulators and practical dilemmas demonstrate whether people know how to apply the rule.

In your organization, does training teach employees how to make decisions, or does it merely present concepts and prohibitions?

How to Evaluate if the 5 Controls Work Together

None of these controls can solve the problem in isolation.

A company can map information effectively but fail to restrict access. It may have a detailed policy but fail to communicate a blackout period on time. It might train internal staff while overlooking external consultants.

Executive Leadership and the Board of Directors can evaluate the program’s consistency using five questions:

  1. Do we know which information can become material?

  2. Can we identify everyone who had access to it?

  3. Are trading rules clear and actionable?

  4. Are third parties and exposed individuals included in governance?

  5. Does training prepare teams for real-world scenarios?

Incomplete answers highlight where the organization should prioritize improvements.

Prevention Requires Consistency, Not Just Paperwork

The modernization of CVM supervision does not change the core principle of insider trading prevention: material, non-public information must be protected and cannot be used to gain an advantage in the market.

What changes is the regulator’s capability to cross-reference data, detect patterns, and target investigations. This makes alignment between access logs, trades, policies, training, and documentation even more critical.

Prepared companies are not those claiming that risk does not exist. They are those that can demonstrate how they identify, control, and monitor that risk.

The five controls outlined in this article offer an objective starting point: map information, restrict access, make trading policies actionable, include third parties, and train people to make responsible decisions.

This content is for informational purposes and does not replace legal or regulatory advice applicable to the specific situation of each organization.

Schedule a Conversation with TothBe

TothBe’s Insider Trading Training for Financial Markets was developed for publicly traded companies, banks, asset managers, insurers, companies going through an IPO, and teams exposed to strategic information.

Featuring an executive tone, practical dilemmas, analytics tracking, and full customization based on your internal policies, our training turns trading and confidentiality rules into responsible daily decisions.

Schedule a demo and talk to TothBe about preparing your organization’s different target audiences to prevent insider trading.

contato@tothbe.com.br

Compartilhe esse post

Veja outros posts:

Contrate os nossos treinamentos e amplie os horizontes da sua empresa.