TABLE OF CONTENTS

    Across the globe, compliance teams are writing personal account dealing (PAD) policies, circulating them, and gathering signed attestations that employees have read and understood the policy. However, there is sometimes a very real disconnect between what exists on paper and what happens in day-to-day operations. Recent enforcement actions in the United States, United Kingdom, Australia, and Hong Kong show clear examples of a widening gap between policy on paper and risk in practice.

    As Kroll’s Director Alasdair Putt observed in a recent MCO (MyComplianceOffice) webinar, a firm can hold “detailed, rigorous, and thorough policies and procedures in place,” but “if the senior management aren’t ensuring that staff understand the compliance framework and the obligations they have as employees of the firm… then it’s easy and very likely that the breaches of the company’s compliance policies or procedures start to happen.”

     

    Key Highlights

    • A written personal account dealing policy can fall flat if daily practice, monitoring and enforcement do not match it.
    • Recent enforcement in the US, UK, Australia and Hong Kong reveals a familiar trend: rules on paper, breaches in practice.
    • For firms operating across borders, policies aligned to the lowest local standard can leave group affiliates exposed.
    • Personal account dealing policy should be set to the highest global standard, with local addenda where a jurisdiction is stricter.
    • Regulators expect consistent, evidenced training and a culture of compliance set from the top.



    Personal Account Dealing Examples of a Global Enforcement Trend

    The following personal account dealing examples come from four different regulators, yet they tell the same story. In each instance, the policy existed on paper, but the day-to-day practice, monitoring or controls behind it did not match up.

    United States: A Code of Ethics Left Unenforced

    In April 2024, the US Securities and Exchange Commission (SEC) settled with a hedge fund adviser that agreed to pay a US$6.5 million penalty.1 Among the findings, the firm had failed to enforce its own code of ethics. Employees had carried out personal securities transactions without obtaining the pre-clearance required by the code. The policy existed on paper, but the day-to-day control that should have enforced it did not. For employees handling sensitive positions, unmonitored personal dealing creates the risk exposure a code of ethics is meant to prevent.

    United Kingdom: Trading on the Information a Policy Should Contain

    In 2025, the Financial Conduct Authority (FCA) secured the conviction of a research analyst at an asset management firm who used confidential, price-sensitive information from his role to trade for profit.2 Over roughly fifteen months he dealt in more than a dozen stocks, routing trades through accounts connected to family members to avoid monitoring, and made more than £960,000 before he was jailed for six years. Firms restrict and monitor personal account dealing precisely to catch this behaviour. On paper the controls existed. In practice, the trading was deliberately structured to slip past them.

    Australia: Personal Account Dealing That Crossed the Line

    In Australia, the Securities and Investments Commission (ASIC) prosecuted a corporate adviser at an advisory firm who dealt in shares for his own account after receiving information about a funding proposal and a draft market announcement.3 He bought shares in the company while holding that information and sold once the news was public and the stock price had jumped. He took a personal profit of over A$57,000 before he was convicted and jailed in 2024. Advisory firms restrict and monitor staff dealing precisely to stop information from a client engagement flowing into a personal trade. On paper, that control existed. In practice, it did not hold.

    Hong Kong: Pre-Approval on Paper Only

    In Hong Kong, the Securities and Futures Commission (SFC) reprimanded and fined a fund manager HK$2 million for failing to supervise its staff and maintain effective controls over staff dealing, and it banned the firm’s former responsible officer for eight months.4 Over a five-year period, the officer carried out more than 2,500 personal trades without the required written pre-approval, dealt in the same securities on the same day as the fund he managed on more than 200 occasions, and joined 12 initial public offerings through personal accounts. We covered the case in A Costly Oversight: Hong Kong SFC Action on Personal Trading. The pre-approval and holding-period rules existed on paper. In practice, nobody enforced them.

     

    The Multi-Jurisdiction Trap

    For global firms, the risk multiplies. As Kroll’s Senior Associate Kiana Leung put it, “having written policies alone are insufficient.” A single group policy rarely maps neatly onto the way regional offices actually operate, and, as Leung noted, “policies are only aligned to lower local standards instead of the stricter global baseline,” which can leave group affiliates exposed.

    “Regional offices fail to cross-reference global restricted lists, or staff in one country accessing non-public material information about a global client can still trade on the same stock because it’s permitted under the local PAD policies.”

    Kiana Leung, Kroll

    Firms must have clear direction about which standard actually governs. Leung recommends applying the strictest applicable rule and building from there: “we have seen firms implementing a local addendum that overrides the global policies whenever Hong Kong law or the SFC regulatory requirements are more stringent.” Aligning to the highest global standard, rather than the lowest local one, is what closes the gap between policy and real exposure. The same principle applies to the information gaps between HR, compliance and the trading desk, where a delayed update, such as an employee moving into an access-person role, can leave personal dealing monitored under the wrong set of rules.

     

     

    Training and Culture as Controls

    Even the best-drafted policy fails without two things behind it: training and culture. Putt pointed to “conducting regular compliance training for all employees, which would hopefully cover the fundamentals of all of their obligations as an employee of a regulated business.” The expectation is not optional.

    “Regulators globally, and… the SFC… very much like to see that general compliance training is being conducted and at least I would say on an annual basis to all employees.”

    Alasdair Putt, Kroll

    Underneath the training sits culture. Breaches, Putt noted, often come down to “the compliance culture a firm is instilled, or maybe a lack thereof,” and the tone from the top. A workforce that understands why the rules exist is far less likely to treat personal dealing as a private matter.

     

    From Policy to Practice in Personal Account Dealing

    The key takeaway for financial firms is that a PAD policy is only as strong as the daily practice, monitoring and controls that sit behind it. For firms operating across jurisdictions, meeting that standard means aligning to the highest global baseline, cross-referencing restricted lists across every office, closing the information gaps between HR, compliance and the trading desk, and evidencing the training that regulators expect to see. Writing the policy is only the beginning. What a firm does next determines whether policy on paper becomes risk mitigation in reality.

     

     

    Turning Policy into Practice with RegTech

    Regulatory technology (RegTech) plays a critical role in turning a written policy into an enforced one. As personal trading activity spreads across securities and digital assets, and across jurisdictions, firms need oversight that runs continuously rather than in periodic, retrospective checks.

    Compliance teams often ask which online platforms offer personal account dealing compliance tools. The answer is a purpose-built RegTech platform that manages employee trading from pre-clearance through to reporting, such as MCO (MyComplianceOffice).

    MCO’s Personal Trading Compliance solution gives compliance teams a structured way to manage the full lifecycle of employee trading. With MCO, firms can:

    • Automate pre-clearance and approvals before employees trade
    • Centralise employee and account data in one place
    • Cross-reference trades against firm-wide restricted and watch lists
    • Monitor personal account dealing with exception-based alerts
    • Maintain complete, audit-ready records across every jurisdiction
    • Apply one consistent global standard, with local rules layered on top

     

    When policy and practice are held together by the same system, firms can evidence effective supervision in line with regulators’ expectations across every market they operate in.

    Are you ready to help your firm meet evolving regulatory expectations? See the MCO complete compliance suite in action now.

     

    References

    Regulatory Enforcement Actions

    1 US Securities and Exchange Commission, “SEC Charges Advisory Firm Senvest Management with Recordkeeping and Other Failures,” 3 April 2024. https://www.sec.gov/newsroom/press-releases/2024-44

    2 Financial Conduct Authority, “Redinel Korfuzi and Oerta Korfuzi sentenced for £1m insider dealing and money laundering,” 2025. https://www.fca.org.uk/news/press-releases/redinel-korfuzi-oerta-korfuzi-sentenced-insider-dealing-money-laundering

    3 Australian Securities and Investments Commission, media release 24-059MR, “Cameron Waugh sentenced to two years imprisonment for insider trading,” 26 March 2024. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2024-releases/24-059mr-cameron-waugh-sentenced-to-two-years-imprisonment-for-insider-trading/

    4 Securities and Futures Commission of Hong Kong, “SFC sanctions Impression Investment Limited and its former responsible officer over staff trading activities,” 9 April 2026. https://apps.sfc.hk/edistributionWeb/gateway/EN/news-and-announcements/news/doc?refNo=26PR55

    MCO Resources

    MyComplianceOffice webinar, “Hong Kong Regulation in Motion: Digital Assets and Conduct Risk.” https://mco.mycomplianceoffice.com/webinar/hong-kong-regulation-in-motion-digital-assets-and-conduct-risk

    MyComplianceOffice article, “A Costly Oversight: Hong Kong SFC Action on Personal Trading.” https://mco.mycomplianceoffice.com/blog/a-costly-oversight-hong-kong-sfc-action-on-personal-trading



    Frequently Asked Questions

    What is personal account dealing?

    Personal account dealing (PAD) is when an employee of a regulated firm buys or sells securities, digital assets or other financial instruments in their own accounts, or in accounts they control or influence. Firms set personal account dealing policies, covering pre-clearance, disclosure and holding periods, to manage conflicts of interest and prevent insider dealing and market abuse.

    Which online platforms offer personal account dealing compliance tools?

    Purpose-built RegTech platforms offer personal account dealing compliance tools. MCO (MyComplianceOffice) is one such platform, giving compliance teams automated pre-clearance, employee account and wallet monitoring, restricted-list checks, and audit-ready reporting across securities and digital assets.

    Why do personal account dealing policies fail?

    Personal account dealing policies fail when the written policy is not matched by daily practice, monitoring and enforcement. Recent enforcement in the United States, United Kingdom, Australia, and Hong Kong shows firms with policies in place that were not enforced, leaving gaps in pre-clearance, restricted lists and connected-account monitoring.

    How should global firms align personal account dealing policies?

    Global firms should align personal account dealing policies to the highest global standard rather than the lowest local one, add a local addendum wherever a jurisdiction is stricter, and cross-reference restricted lists across every office.