Skip to main content
Your Compliance Program Faces Two Regulators NowCompliance Governance
5 min readFor Compliance Training Managers

Your Compliance Program Faces Two Regulators Now

The SEC and FDA signed a three-year Memorandum of Understanding (MOU) in August 2026 to share information and coordinate enforcement. If your company operates in the life sciences sector, this isn't just a regulatory headline. It's a structural shift in how oversight works.

When two federal agencies formalize information-sharing protocols, they're creating a system where a disclosure issue flagged by one regulator can immediately surface in the other's enforcement pipeline. Your compliance program needs to account for that reality.

This checklist helps you assess whether your current controls can handle coordinated multi-agency scrutiny.

Prerequisites

Before you work through this checklist, confirm:

  • You have a current inventory of all FDA-regulated products or activities your company engages in.
  • You know which business units prepare SEC filings and which prepare FDA submissions.
  • You can identify who owns disclosure decisions when FDA developments affect financial reporting.
  • Your legal and compliance teams have reviewed the Federal Sentencing Guidelines for Organizations requirements for due diligence across regulatory domains.

If any of these are unclear, pause and document them first. Multi-agency compliance starts with knowing what you're managing.

Checklist Items

1. Map your disclosure trigger points

Identify every business event that requires both FDA action and SEC disclosure. This includes clinical trial results, FDA warning letters, product approvals or denials, manufacturing issues, and adverse event reports.

Good looks like: A matrix showing each trigger, the responsible business owner, the timeline for each agency's requirement, and the internal approval chain. Your SEC disclosure team can see FDA milestones coming, and your regulatory affairs team understands when their work creates disclosure obligations.

2. Establish a cross-functional disclosure committee

Create a standing group that includes representatives from regulatory affairs, investor relations, legal, compliance, and finance. This team reviews material FDA developments before they become public.

Good looks like: The committee meets on a set schedule (at minimum monthly, more often during active FDA processes). Meeting minutes document what was discussed, what disclosure decisions were made, and who approved them. The committee has clear authority to escalate issues and delay announcements when necessary.

3. Build dual-timeline tracking for material events

Set up a system that tracks both FDA submission deadlines and SEC disclosure windows for the same underlying event. The SEC's materiality standard and the FDA's regulatory timelines don't align automatically.

Good looks like: Your project management or compliance platform flags when an FDA milestone is approaching and automatically prompts a materiality assessment for SEC purposes. You're not relying on someone to remember that a clinical trial readout in three weeks might require an 8-K filing.

4. Update your record retention policy for shared information

Information you provide to the FDA can now flow to the SEC under the MOU's information-sharing protocols. Your Record Retention Policy must account for this.

Good looks like: Your policy explicitly states that FDA submissions, correspondence, and supporting documentation are retained with the same rigor as SEC filings. You've documented the retention period, the custodians, and the retrieval process. Both agencies can request the same records, and you can produce them consistently.

5. Train disclosure decision-makers on multi-agency materiality

The people who decide what's material for SEC purposes need to understand how FDA developments affect that calculus. A rejected drug application isn't just a regulatory setback; it's potentially material nonpublic information.

Good looks like: Your training program includes case studies showing how FDA actions have triggered SEC enforcement in the past. Decision-makers can articulate the difference between FDA confidentiality rules and SEC materiality obligations. They know when to consult both legal teams before making a call.

6. Review your internal accounting controls for FDA-related estimates

FDA actions directly affect revenue recognition, asset valuations, and contingent liabilities. Your Internal Accounting Controls need to capture this.

Good looks like: Your controls explicitly require finance to consult regulatory affairs before finalizing estimates tied to FDA-regulated products. You have a documented process for updating assumptions when FDA guidance changes or when the agency requests additional information. External auditors can trace FDA developments to accounting adjustments.

7. Assess third-party intermediaries who interact with both agencies

Contract research organizations, clinical trial sites, consultants, and lobbyists may communicate with FDA and SEC on your behalf. These are Third-Party Intermediaries under your compliance program.

Good looks like: Your due diligence process for these vendors includes questions about their information security, their understanding of confidentiality requirements, and their protocols for coordinating with your internal teams. Contracts specify that they cannot make disclosures to either agency without your prior approval.

8. Establish an information-sharing protocol with outside counsel

Your FDA regulatory counsel and your securities counsel need to coordinate. They can't operate in silos when the agencies themselves are sharing information.

Good looks like: You've designated a single point of contact (usually your chief legal officer or compliance officer) who ensures both legal teams are briefed on material developments. You have a written protocol for when and how the two practices communicate. Privilege logs reflect this coordination.

9. Update your Standards of Business Conduct to address dual-agency scenarios

Your code should explicitly tell employees what to do when they're uncertain whether something needs to be disclosed, especially if it involves FDA matters.

Good looks like: The code includes language like: "If you learn of an FDA development that could affect our financial results or stock price, report it immediately to [designated role]." Employees understand that FDA confidentiality doesn't override securities law obligations.

10. Conduct a tabletop exercise simulating coordinated enforcement

Test your response when both agencies are asking questions about the same event. This reveals gaps before they matter.

Good looks like: You've run a scenario where the FDA issues a warning letter and the SEC opens an inquiry into whether you disclosed it properly. Your team knows who leads the response, how information flows between agency interactions, and where potential conflicts arise. You've documented lessons learned and updated procedures accordingly.

Common Mistakes

Treating FDA and SEC compliance as separate workstreams. The MOU exists because these agencies recognize their oversight intersects. Your compliance program should reflect that before an enforcement action forces the point.

Assuming FDA confidentiality rules excuse SEC disclosure. They don't. Materiality under securities law is a separate analysis. When in doubt, you disclose.

Failing to update disclosure controls after FDA interactions. Every FDA meeting, submission, or correspondence is a potential disclosure trigger. If your Disclosure Controls and Procedures don't capture these, you're flying blind.

Underestimating how quickly information moves between agencies now. The MOU formalizes what was already happening informally. Assume anything you tell one agency could reach the other within days, not months.

Next Steps

Schedule a meeting with your regulatory affairs and investor relations leads in the next two weeks. Walk through this checklist together and assign ownership for each item. Set a 90-day deadline to close any gaps.

If you're in life sciences and you haven't updated your compliance program since August 2026, you're operating under an outdated model. The agencies have adapted. Your program should too.

You Might Also Like