When prosecutors charged 30 people in a multi-firm insider trading scheme, the indictment revealed a pattern you may have worried about: a trusted insider accessing documents they weren't assigned to, extracting Material Nonpublic Information from nearly 30 merger and acquisition deals, and trading on it for years. The document management systems logged every access, but no one noticed until federal investigators pieced it together.
If you're responsible for information governance at a law firm or corporate legal department, this isn't just a cautionary tale. It's a blueprint for what you need to fix right now.
Why This Matters
Your document management system already tracks who opens what. That's not the vulnerability. The vulnerability is that no one's watching those logs in real time, and your access controls expand automatically as deals staff up. The alleged scheme exploited this gap: attorneys accessed documents across matters they weren't staffed on, while the firms' systems logged every breach without triggering an alert.
Policies alone won't solve this. The victim law firms likely had strict policies against misuse of Material Nonpublic Information and provided annual training. But policies don't stop someone who's decided to act unethically. What stops them is a system that makes unauthorized access visible and consequential before the trade happens.
What You Need Before Starting
Before redesigning access controls, audit what you have:
Document management system logs. Pull six months of access records. Identify who's accessing documents outside their assigned matters, how often, and whether anyone's reviewing those logs now.
Matter staffing records. Your conflicts system or matter management platform should show who's assigned to each engagement. If it doesn't, you can't automate access control.
Code name discipline. If your M&A team uses code names inconsistently or stores real company names in easily searchable fields, you're making it easier for insiders to identify valuable targets.
A small cross-functional team. Include someone from IT who understands your document platform's permissions architecture, someone from legal who knows how M&A staffing works, and someone from compliance who can design monitoring protocols without drowning in false positives.
Step-by-Step Implementation
Step 1: Restrict default access to deal folders.
Stop giving firmwide access to M&A documents. When a new matter opens, the document management system should create a folder with access limited to the partner who opened it. No one else can view it until they're explicitly added. This creates necessary friction.
Step 2: Tie access rights to matter staffing.
If your conflicts system tracks who's assigned to a matter, build an integration that syncs those assignments to document permissions. When someone's added to the staffing list, they get folder access automatically. When they roll off, access revokes within 24 hours. This eliminates the manual IT ticket process that causes partners to grant overly broad access "just in case."
Step 3: Log and flag cross-matter access.
Configure your document management system to flag when someone accesses documents in a matter they're not staffed on. Don't block it outright (sometimes there are legitimate reasons), but generate a daily report for compliance review. The report should show:
- Who accessed documents outside their assigned matters
- Which matters they accessed
- How many documents they opened
- Whether this is a pattern (more than two matters in a week)
Step 4: Automate Blackout Period reminders.
When your system detects that an attorney has accessed M&A documents in the past 90 days, it should trigger an automated reminder about Blackout Period restrictions and trading prohibitions. Send these monthly. Frequency matters when you're trying to interrupt someone who's considering a trade.
Step 5: Require attestation for sensitive matters.
For transactions above a certain threshold or involving publicly traded companies, require everyone with document access to complete a brief attestation every 30 days: "I confirm I have not traded securities in [CODE NAME] or shared Material Nonpublic Information with anyone outside the deal team." The attestation isn't foolproof, but it creates a documented moment of reflection and establishes a paper trail if someone lies.
Step 6: Train on the logs, not just the rules.
Your annual insider trading training probably covers what Material Nonpublic Information is and why trading on it is illegal. Add a new section: "Your document access is logged and reviewed. Accessing documents outside your assigned matters without a business reason will trigger a compliance inquiry." Show a redacted example of an access log. Make it concrete.
Validation: How to Verify It Works
Run these tests quarterly:
Access control test. Have someone from compliance try to open documents in an M&A matter they're not staffed on. They should be blocked or flagged within 24 hours.
Staffing sync test. Remove someone from a matter's staffing list and confirm their document access revokes automatically within your defined window.
Log review test. Pull your cross-matter access report and investigate three flagged instances. Can you quickly determine whether the access was legitimate? If it takes more than 15 minutes per incident, your logging isn't specific enough.
Attestation compliance test. Check what percentage of people with access to sensitive matters completed their monthly attestation. If it's below 95%, your reminder system isn't working.
Ongoing Tasks
Weekly: Review the cross-matter access report. Investigate anything that looks like pattern behavior (same person, multiple unrelated matters, high document counts).
Monthly: Audit matter staffing lists against document permissions. Look for people who still have access weeks after rolling off a deal.
Quarterly: Meet with your M&A practice group leaders. Ask whether the access controls are creating unreasonable friction. If associates are constantly requesting emergency access for legitimate reasons, you've made the controls too restrictive. Adjust.
Annually: Refresh your insider trading training to include real examples of access log reviews and enforcement outcomes. Don't name names, but make it clear the logs are actively monitored.
After any personnel change in M&A: Audit that person's document access and trading activity for the prior 90 days. If they're leaving voluntarily, it's a natural off-boarding step. If they're being terminated, it's essential.
The indictment names six victim law firms. They all had policies and systems. What they didn't have was someone watching the logs in real time and asking why an attorney was digging through documents on deals they weren't working on. You can't rely on people to not act unethically, but you can make it much harder for them to do it invisibly.



