Across the globe, compliance teams are writing personal account dealing (PAD) policies, circulating them, and gathering signed attestations that employees have read and understood the policy. However, there is sometimes a very real disconnect between what exists on paper and what happens in day-to-day operations. Recent enforcement actions in the United States, United Kingdom, Australia, and Hong Kong show clear examples of a widening gap between policy on paper and risk in practice.
As Kroll’s Director Alasdair Putt observed in a recent MCO (MyComplianceOffice) webinar, a firm can hold “detailed, rigorous, and thorough policies and procedures in place,” but “if the senior management aren’t ensuring that staff understand the compliance framework and the obligations they have as employees of the firm… then it’s easy and very likely that the breaches of the company’s compliance policies or procedures start to happen.”
The following personal account dealing examples come from four different regulators, yet they tell the same story. In each instance, the policy existed on paper, but the day-to-day practice, monitoring or controls behind it did not match up.
In April 2024, the US Securities and Exchange Commission (SEC) settled with a hedge fund adviser that agreed to pay a US$6.5 million penalty.1 Among the findings, the firm had failed to enforce its own code of ethics. Employees had carried out personal securities transactions without obtaining the pre-clearance required by the code. The policy existed on paper, but the day-to-day control that should have enforced it did not. For employees handling sensitive positions, unmonitored personal dealing creates the risk exposure a code of ethics is meant to prevent.
In 2025, the Financial Conduct Authority (FCA) secured the conviction of a research analyst at an asset management firm who used confidential, price-sensitive information from his role to trade for profit.2 Over roughly fifteen months he dealt in more than a dozen stocks, routing trades through accounts connected to family members to avoid monitoring, and made more than £960,000 before he was jailed for six years. Firms restrict and monitor personal account dealing precisely to catch this behaviour. On paper the controls existed. In practice, the trading was deliberately structured to slip past them.
In Australia, the Securities and Investments Commission (ASIC) prosecuted a corporate adviser at an advisory firm who dealt in shares for his own account after receiving information about a funding proposal and a draft market announcement.3 He bought shares in the company while holding that information and sold once the news was public and the stock price had jumped. He took a personal profit of over A$57,000 before he was convicted and jailed in 2024. Advisory firms restrict and monitor staff dealing precisely to stop information from a client engagement flowing into a personal trade. On paper, that control existed. In practice, it did not hold.
In Hong Kong, the Securities and Futures Commission (SFC) reprimanded and fined a fund manager HK$2 million for failing to supervise its staff and maintain effective controls over staff dealing, and it banned the firm’s former responsible officer for eight months.4 Over a five-year period, the officer carried out more than 2,500 personal trades without the required written pre-approval, dealt in the same securities on the same day as the fund he managed on more than 200 occasions, and joined 12 initial public offerings through personal accounts. We covered the case in A Costly Oversight: Hong Kong SFC Action on Personal Trading. The pre-approval and holding-period rules existed on paper. In practice, nobody enforced them.
For global firms, the risk multiplies. As Kroll’s Senior Associate Kiana Leung put it, “having written policies alone are insufficient.” A single group policy rarely maps neatly onto the way regional offices actually operate, and, as Leung noted, “policies are only aligned to lower local standards instead of the stricter global baseline,” which can leave group affiliates exposed.
“Regional offices fail to cross-reference global restricted lists, or staff in one country accessing non-public material information about a global client can still trade on the same stock because it’s permitted under the local PAD policies.”
Kiana Leung, Kroll
Firms must have clear direction about which standard actually governs. Leung recommends applying the strictest applicable rule and building from there: “we have seen firms implementing a local addendum that overrides the global policies whenever Hong Kong law or the SFC regulatory requirements are more stringent.” Aligning to the highest global standard, rather than the lowest local one, is what closes the gap between policy and real exposure. The same principle applies to the information gaps between HR, compliance and the trading desk, where a delayed update, such as an employee moving into an access-person role, can leave personal dealing monitored under the wrong set of rules.
Even the best-drafted policy fails without two things behind it: training and culture. Putt pointed to “conducting regular compliance training for all employees, which would hopefully cover the fundamentals of all of their obligations as an employee of a regulated business.” The expectation is not optional.
“Regulators globally, and… the SFC… very much like to see that general compliance training is being conducted and at least I would say on an annual basis to all employees.”
Alasdair Putt, Kroll
Underneath the training sits culture. Breaches, Putt noted, often come down to “the compliance culture a firm is instilled, or maybe a lack thereof,” and the tone from the top. A workforce that understands why the rules exist is far less likely to treat personal dealing as a private matter.
The key takeaway for financial firms is that a PAD policy is only as strong as the daily practice, monitoring and controls that sit behind it. For firms operating across jurisdictions, meeting that standard means aligning to the highest global baseline, cross-referencing restricted lists across every office, closing the information gaps between HR, compliance and the trading desk, and evidencing the training that regulators expect to see. Writing the policy is only the beginning. What a firm does next determines whether policy on paper becomes risk mitigation in reality.
Regulatory technology (RegTech) plays a critical role in turning a written policy into an enforced one. As personal trading activity spreads across securities and digital assets, and across jurisdictions, firms need oversight that runs continuously rather than in periodic, retrospective checks.
Compliance teams often ask which online platforms offer personal account dealing compliance tools. The answer is a purpose-built RegTech platform that manages employee trading from pre-clearance through to reporting, such as MCO (MyComplianceOffice).
MCO’s Personal Trading Compliance solution gives compliance teams a structured way to manage the full lifecycle of employee trading. With MCO, firms can:
When policy and practice are held together by the same system, firms can evidence effective supervision in line with regulators’ expectations across every market they operate in.
Are you ready to help your firm meet evolving regulatory expectations? See the MCO complete compliance suite in action now.
1 US Securities and Exchange Commission, “SEC Charges Advisory Firm Senvest Management with Recordkeeping and Other Failures,” 3 April 2024. https://www.sec.gov/newsroom/press-releases/2024-44
2 Financial Conduct Authority, “Redinel Korfuzi and Oerta Korfuzi sentenced for £1m insider dealing and money laundering,” 2025. https://www.fca.org.uk/news/press-releases/redinel-korfuzi-oerta-korfuzi-sentenced-insider-dealing-money-laundering
3 Australian Securities and Investments Commission, media release 24-059MR, “Cameron Waugh sentenced to two years imprisonment for insider trading,” 26 March 2024. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2024-releases/24-059mr-cameron-waugh-sentenced-to-two-years-imprisonment-for-insider-trading/
4 Securities and Futures Commission of Hong Kong, “SFC sanctions Impression Investment Limited and its former responsible officer over staff trading activities,” 9 April 2026. https://apps.sfc.hk/edistributionWeb/gateway/EN/news-and-announcements/news/doc?refNo=26PR55
MyComplianceOffice webinar, “Hong Kong Regulation in Motion: Digital Assets and Conduct Risk.” https://mco.mycomplianceoffice.com/webinar/hong-kong-regulation-in-motion-digital-assets-and-conduct-risk
MyComplianceOffice article, “A Costly Oversight: Hong Kong SFC Action on Personal Trading.” https://mco.mycomplianceoffice.com/blog/a-costly-oversight-hong-kong-sfc-action-on-personal-trading
Personal account dealing (PAD) is when an employee of a regulated firm buys or sells securities, digital assets or other financial instruments in their own accounts, or in accounts they control or influence. Firms set personal account dealing policies, covering pre-clearance, disclosure and holding periods, to manage conflicts of interest and prevent insider dealing and market abuse.
Purpose-built RegTech platforms offer personal account dealing compliance tools. MCO (MyComplianceOffice) is one such platform, giving compliance teams automated pre-clearance, employee account and wallet monitoring, restricted-list checks, and audit-ready reporting across securities and digital assets.
Personal account dealing policies fail when the written policy is not matched by daily practice, monitoring and enforcement. Recent enforcement in the United States, United Kingdom, Australia, and Hong Kong shows firms with policies in place that were not enforced, leaving gaps in pre-clearance, restricted lists and connected-account monitoring.
Global firms should align personal account dealing policies to the highest global standard rather than the lowest local one, add a local addendum wherever a jurisdiction is stricter, and cross-reference restricted lists across every office.