Skip to main content
Category: Insider Trading Controls

Information Barrier

Also known as: IB, Information Barriers, Ethical Wall
Simply put

An information barrier is a policy or control that stops certain people or groups within an organization from exchanging or viewing restricted information. It is used to protect confidential information from improper disclosure and to prevent conflicts of interest. Barriers can be applied through internal rules as well as technical controls in collaboration platforms.

Formal definition

An information barrier is a compliance control comprising policies, and often supporting technical enforcement, that restricts communication, collaboration, or the flow of confidential information between defined individuals or groups where such exchange could create a conflict of interest or result in unauthorized disclosure. Implementations range from internal procedural controls to platform-level policy engines that block two-way communication and content visibility between segmented user populations (for example, Microsoft Purview Information Barriers within Microsoft Teams and related collaboration environments). Information barriers are one component of a broader compliance program and do not by themselves constitute a complete conflicts-of-interest or confidentiality regime; their effectiveness depends on scope definition, correct configuration, and ongoing administration. This entry is educational and not a substitute for professional legal advice; the reasonableness and adequacy of a given information barrier can vary by jurisdiction and regulatory context and may require qualified counsel.

Why it matters

Information barriers address two persistent risks in organizations that handle confidential or price-sensitive information: improper disclosure and conflicts of interest. When individuals or teams have access to information that could be misused if shared with certain colleagues, an unmanaged flow of that information can expose the organization to regulatory, legal, and reputational harm. Barriers are a mechanism for keeping defined groups separated so that restricted information does not move where it should not.

Because the reasonableness and adequacy of a given information barrier can vary by jurisdiction and regulatory context, compliance teams cannot treat these controls as a one-size-fits-all solution. Guidance such as that reflected in UK legal sources notes that information barriers are appropriate only where it is reasonable to use them, which underscores that their suitability depends on the specific circumstances and may require qualified legal counsel to assess. An information barrier is educational to understand but sits within a broader confidentiality and conflicts-of-interest framework; it does not by itself constitute a complete regime.

The effectiveness of an information barrier depends on how well its scope is defined, whether it is correctly configured, and whether it is administered on an ongoing basis. A poorly scoped or misconfigured barrier can create a false sense of protection, so organizations should treat implementation and maintenance as continuing responsibilities rather than a one-time setup. Exact regulatory requirements should be confirmed against primary sources and applicable local law.

Who it's relevant to

Compliance officers and program managers
These readers determine when an information barrier is an appropriate control, how it fits within a broader confidentiality and conflicts-of-interest program, and how its scope should be defined. They are responsible for recognizing that a barrier is one component and does not, on its own, satisfy an entire compliance program.
Legal and audit teams
Legal teams assess whether it is reasonable to use an information barrier in a given situation, a judgment that can vary by jurisdiction and regulatory context and may require qualified counsel. Audit teams evaluate whether barriers are correctly scoped, configured, and maintained over time.
IT and collaboration platform administrators
Where barriers are enforced technically, such as through Microsoft Purview Information Barriers in Microsoft Teams, administrators configure the policy engines that block two-way communication and content visibility between segmented user populations, and they maintain those configurations as membership and requirements change.
Learning and development staff
Training staff help affected employees understand which restrictions apply to them and why, supporting the procedural side of a barrier so that individuals do not attempt to circumvent controls or inadvertently share restricted information through channels the technical enforcement does not cover.

Inside IB

Physical and Systems Separation
Arrangements that restrict the flow of material non-public or sensitive information between individuals, teams, or business units, including segregated workspaces, access-controlled systems, and restricted document repositories.
Access Controls and Need-to-Know Restrictions
Policies and technical controls limiting information access to personnel with a legitimate business need, often implemented through user permissions, restricted lists, and authentication measures.
Wall-Crossing Procedures
Documented processes governing when and how an individual on one side of a barrier may be brought over to access restricted information, typically requiring authorization, logging, and confidentiality undertakings.
Policies and Written Procedures
The internal governance documents that define the barrier's scope, the personnel and business lines covered, escalation paths, and consequences for breaches. This is a policy and control component rather than a training module in itself.
Monitoring and Recordkeeping
Ongoing surveillance, restricted-list maintenance, and audit trails intended to detect improper information flow and evidence that the barrier operates as designed. This function is part of a broader monitoring and auditing system, not a substitute for it.
Training and Awareness
Instruction that helps covered personnel understand their obligations under the barrier. This is one supporting component and does not by itself establish or maintain an effective information barrier.

Common questions

Answers to the questions practitioners most commonly ask about IB.

Is an information barrier the same as a data security or IT access control?
No. Although information barriers often rely on technical access controls to function, the term refers to a broader governance mechanism intended to prevent the improper flow of sensitive information between individuals or groups with conflicting interests. Data security addresses protection against unauthorized external or internal access generally, while an information barrier addresses controlled separation between defined internal populations. The two overlap in implementation but are distinct in purpose, and IT controls alone do not constitute an information barrier without the accompanying policies, procedures, and oversight.
Does having an information barrier in place guarantee that conflicts of interest or improper information sharing will not occur?
No. An information barrier is intended to reduce the risk of improper information flow and to support the management of conflicts of interest, but it does not guarantee prevention. Its effectiveness depends on design, implementation, monitoring, and the conduct of the individuals subject to it. A barrier can be circumvented, applied inconsistently, or undermined by inadequate oversight. It is generally regarded as one control among several rather than a complete safeguard, and outcomes depend on context and enforcement.
Who should be responsible for designing and maintaining an information barrier?
Responsibility is typically shared across compliance, legal, and relevant business functions, often with support from IT for technical controls. Compliance or legal generally owns the policy framework and monitoring, while business units help identify which populations and information require separation. Because the appropriate structure varies by organization and by the specific conflicts being managed, and because it may touch matters requiring qualified legal counsel, roles should be defined explicitly and documented. This entry is educational and not a substitute for professional advice.
What elements are commonly included when implementing an information barrier?
Implementations commonly combine written policies defining the separated populations and restricted information, physical or logical access restrictions, procedures for controlled crossing of the barrier when necessary, recordkeeping of who has access and any exceptions, and periodic monitoring or review. Training for affected personnel is often included so individuals understand their obligations. The specific combination depends on the organization's structure and the nature of the conflicts being addressed, and no single element is sufficient on its own.
How is a controlled crossing of an information barrier typically handled?
Controlled crossings, sometimes referred to as bringing someone over the barrier, are generally handled through a documented approval process that records who is granted access, the reason, the duration, and any restrictions that apply while the individual has access. Procedures often designate an approving authority and address the individual's obligations upon completion. Because such crossings can affect conflict management and may raise legal considerations, the process should be defined in advance and documented, and specific requirements may vary by jurisdiction and warrant legal counsel.
How should the effectiveness of an information barrier be monitored over time?
Monitoring is generally approached through periodic review of access records, exception logs, and any crossing approvals, along with checks that technical and physical controls remain in place and functioning. Some organizations conduct testing or auditing to identify gaps or inconsistent application. Monitoring and auditing is a distinct program function from the barrier itself and supports its ongoing reliability rather than replacing it. The appropriate scope and frequency depend on the organization's risk profile and available resources.

Common misconceptions

An information barrier is primarily an ethics concept about doing the right thing.
An information barrier sits toward the compliance end of the spectrum. It is a control designed to satisfy legal, regulatory, and policy obligations regarding the handling of sensitive information, with defined procedures and consequences, rather than a values-based judgment exercise. Specific obligations vary by jurisdiction and industry and should be confirmed with qualified counsel.
Having an information barrier policy guarantees the organization will prevent improper information flow or misuse.
No barrier guarantees prevention of misconduct or provides automatic legal protection. A barrier is intended to reduce the risk of improper information flow, and its effectiveness depends on implementation, monitoring, and the conduct of covered personnel.
Training staff on the barrier is sufficient to establish the control.
Training is only one supporting element. An information barrier also depends on access controls, physical and systems separation, written procedures, monitoring, and recordkeeping, which together form the control. Training does not replace these other components.

Best practices

Document the barrier's scope in writing, clearly identifying the covered business units, personnel, and categories of restricted information, and confirm any jurisdiction-specific obligations with qualified legal counsel.
Implement layered access controls on a need-to-know basis, combining technical restrictions with physical or systems separation rather than relying on any single measure.
Establish formal wall-crossing procedures that require authorization, confidentiality undertakings, and logging before anyone is granted access to restricted information.
Integrate the barrier into the organization's broader monitoring and auditing function, maintaining audit trails and restricted lists to help detect and evidence improper information flow.
Provide targeted training so covered personnel understand their obligations, while treating training as a supporting element rather than the control itself.
Periodically review and test the barrier's design and operation against current regulatory expectations, recognizing that specific requirements vary by jurisdiction and should be verified against primary sources and qualified advisors.