When a compliance officer's personal conversation leads to an SEC enforcement action, it's time to check whether your team understands the boundaries of their role, both at work and in personal settings.
The recent case involving Benjamin Tesfaye and his girlfriend, a senior director of ethics and compliance, highlights a vulnerability many organizations overlook: what compliance professionals should and shouldn't discuss outside the office. Tesfaye profited $18,700 from trading on acquisition information his girlfriend shared during a phone call. He paid $20,836 in disgorgement and interest, plus $18,668 in civil penalties.
The compliance officer didn't name the target company or hand over documents. She simply mentioned that "very big things" were happening and that she was excited about an upcoming acquisition. That was enough.
This checklist helps you assess whether your compliance team, and anyone else handling Material Nonpublic Information, has the guardrails they need to protect themselves and your organization.
Prerequisites
Before you work through this checklist, confirm:
- You've identified all roles with routine access to Material Nonpublic Information, including compliance, HR, internal audit, IT, and executive assistants.
- Your organization has a written policy on confidential information and insider trading.
- You have a process for tracking who knows what during sensitive transactions or investigations.
Confidentiality and Personal Boundaries Checklist
1. Role-specific confidentiality training covers personal relationships
Your compliance team receives training that explicitly addresses what they can and cannot discuss with spouses, partners, roommates, and close friends, not just "don't share confidential information" in the abstract.
What good looks like: Training includes realistic scenarios where a compliance officer is asked, "How was your day?" or "Why are you working late?" and provides specific language they can use to deflect without creating suspicion or damaging the relationship.
2. Material Nonpublic Information is defined with examples relevant to each role
Your policy doesn't just cite the legal definition. It lists the types of information each role handles that would qualify: pending acquisitions, investigation findings, financial results before release, workforce reductions, regulatory actions, contract losses.
What good looks like: A compliance officer can look at a list and immediately recognize that due diligence activity on a potential acquisition qualifies, even if they don't know all the financial details.
3. Physical and digital workspace separation is required when working from home
Anyone handling Material Nonpublic Information must work in a space where household members cannot overhear calls or see screens, and your policy states this clearly.
What good looks like: During onboarding, employees who handle sensitive information sign an acknowledgment that they're responsible for maintaining workspace separation at home, and managers check in periodically about whether this is feasible.
4. Compliance officers receive guidance on managing personal curiosity
Your team understands that family and friends will ask questions, especially during periods of visible activity (late nights, travel, stress). They have strategies for responding without lying or sharing information.
What good looks like: Training includes a decision tree: "If someone asks why you're working late, you can say you're busy with a project. You cannot say it's related to an acquisition, investigation, or regulatory matter, even in vague terms."
5. Personal trading restrictions apply to household members
Your policy explicitly states that anyone living with or closely connected to someone with access to Material Nonpublic Information is subject to the same trading restrictions, and employees must communicate this to their household.
What good looks like: Employees receive an annual reminder to discuss trading restrictions with anyone who shares their household or has access to their financial accounts, and they attest that they've had this conversation.
6. There's a process for employees to self-report potential breaches
If a compliance officer realizes they said too much or that a family member may have traded on information, they know how to report it internally before it becomes an enforcement issue.
What good looks like: Your policy includes a clear, non-punitive process for self-reporting, and employees understand that early disclosure is always better than waiting for an external investigation.
7. Compliance officers can request temporary communication restrictions
During high-stakes matters (acquisitions, major investigations, Blackout Periods), compliance team members can ask to be excused from discussing work at all, and the organization supports this boundary.
What good looks like: A compliance officer working on acquisition due diligence can tell their manager, "I need to go dark on work discussions at home for the next two weeks," and the manager understands this is a risk management measure, not a personal issue.
8. Exit interviews include confidentiality reminders
When a compliance officer or anyone with access to Material Nonpublic Information leaves, your exit process includes a specific discussion about ongoing confidentiality obligations and personal trading restrictions during any transition period.
What good looks like: Departing employees sign a separation agreement that restates their duty to protect confidential information, and HR confirms they understand that certain information remains protected indefinitely.
Common Mistakes
Assuming compliance officers "just know" the rules. The Tesfaye case involved a senior director of ethics and compliance. Title and expertise don't eliminate the risk of a lapse in judgment during a casual conversation with someone you trust.
Treating confidentiality as a workplace-only obligation. Most training focuses on not discussing matters at the office or in public. The harder boundary is at home, where the risk feels abstract and the pressure to share feels natural.
Failing to address the "how was your day?" problem. Telling someone they can't discuss work at all is unrealistic. They need specific language for deflecting questions without creating relationship tension or suspicion.
Overlooking indirect disclosures. The compliance officer in the Tesfaye case didn't name the acquisition target. She shared enough context that her boyfriend could deduce it with one follow-up question to a family member. Indirect clues are still violations.
Ignoring household member trading. Even if your employee doesn't trade, if their spouse or partner does, your organization still faces reputational and legal risk. The policy must extend to anyone in the household.
Next Steps
If you found gaps in this checklist, start here:
- Schedule a confidentiality refresher for anyone with routine access to Material Nonpublic Information, with a specific module on personal relationships and household boundaries.
- Revise your insider trading policy to include explicit guidance on what compliance officers and other high-access roles can and cannot discuss outside work.
- Add a question to your annual Attestation and Certification: "Have you discussed trading restrictions and confidentiality obligations with members of your household?"
- Create a self-reporting process for potential confidentiality breaches, and communicate it widely so employees know it exists before they need it.
The Tesfaye case is a reminder that compliance professionals are human. They get excited about their work. They want to share their lives with the people they care about. Your job is to give them the tools to do that without compromising the information they're trusted to protect.



