Skip to main content
Category: Insider Trading Controls

Insider List

Also known as: Insider Register, MNPI Access List
Simply put

An insider list is a confidential record identifying every individual who has access to inside information (material, non-public, price-sensitive information) about a company whose financial instruments are publicly traded. It is maintained by the company issuing those instruments and by parties acting on its behalf, such as advisers. The list helps track who knew what and when, supporting the prevention and investigation of insider dealing.

Formal definition

An insider list is a record maintained by an issuer, or by persons acting on the issuer's behalf (for example, advisers), of all individuals who have access to inside information relating to the issuer or its financial instruments, where 'inside information' is precise, non-public information that would likely have a significant effect on the price of those instruments. As described in the evidence, the concept is framed within the EU/UK Market Abuse Regulation (MAR) regime; MAR is jurisdiction-specific and its detailed content, formatting, and retention requirements should be confirmed against the primary regulatory text and qualified legal counsel. The insider list is a monitoring, recordkeeping, and information-management control rather than a training component; it is one element of a broader market-abuse compliance framework and does not by itself constitute a complete compliance program. This entry is educational and not a substitute for professional legal advice.

Why it matters

An insider list is a core recordkeeping and information-management control in the effort to prevent and investigate insider dealing. Because it identifies every individual who has access to inside information, and, in principle, when that access occurred, it gives an issuer and its regulators a factual basis for reconstructing who knew what and when. This traceability is what makes the list useful in distinguishing legitimate access from suspected market abuse. It is a compliance instrument focused on adherence to specific regulatory obligations, rather than a broader values-based ethics measure.

As framed in the evidence, the insider list concept sits within the EU/UK Market Abuse Regulation (MAR) regime, which is jurisdiction-specific. The detailed obligations governing what a list must contain, how it must be formatted, and how long it must be retained are set by the primary regulatory text and should be confirmed against those sources and qualified legal counsel rather than assumed to apply universally. Firms operating across multiple jurisdictions cannot presume that MAR-style insider list requirements carry over to markets governed by other regimes.

It is important to keep the insider list in proportion: it is one element of a wider market-abuse compliance framework and does not, on its own, constitute a complete compliance program. Maintaining an accurate list is intended to support monitoring and investigation, but its value depends on implementation, timely updates, accurate access records, and integration with wider controls. This entry is educational and not a substitute for professional legal advice.

Who it's relevant to

Compliance officers and program managers
Compliance teams at issuers and at firms acting on an issuer's behalf are typically responsible for maintaining the insider list as part of a wider market-abuse compliance framework. They need to ensure the record accurately captures who has access to inside information and for how long, while recognizing that the list is one control among many rather than a stand-alone program.
Legal and advisory teams
Because the insider list concept is framed within the jurisdiction-specific MAR regime, legal counsel and external advisers should confirm the precise content, formatting, and retention requirements against the primary regulatory text. Advisers acting on an issuer's behalf may themselves need to maintain lists, making an accurate understanding of the obligation essential.
Audit and monitoring functions
Teams responsible for monitoring and investigation rely on the insider list as a factual record for reconstructing who had access to inside information and when. This supports the prevention and investigation of insider dealing, though its usefulness depends on the list being kept current and accurate.
Learning and development staff
Training teams should understand that the insider list is a recordkeeping control, not a training component. Awareness programs can reinforce why access to inside information is tracked and why individuals may be added to a list, but such training does not substitute for maintaining the list itself.

Inside Insider List

Identity of Insiders
The names of persons who have access to inside information, whether they are employees, officers, or third parties such as advisers, auditors, or consultants engaged by the issuer.
Reason for Inclusion
A statement of why each listed person has access to inside information, identifying the function or role that grants that access.
Date and Time of Access
The point at which a person gained access to the inside information, and where relevant the date and time they ceased to have such access.
Personal Identifying Data
Information sufficient to identify each listed individual, which may include contact and identification details as required by applicable regulation. The precise data fields required are jurisdiction-specific and should be confirmed against primary sources.
Nature of the Inside Information
An indication of the specific deal, event, or matter to which the list relates, since insider lists are commonly maintained on a per-event or per-matter basis.

Common questions

Answers to the questions practitioners most commonly ask about Insider List.

Is maintaining an insider list the same as having an insider trading compliance program?
No. An insider list is a single record-keeping component, not a complete program. It documents who has access to specific inside information at a given time, but it does not itself impose trading restrictions, deliver training, or monitor transactions. A broader insider trading compliance framework typically also includes a code of conduct, trading windows and pre-clearance procedures, training modules, and monitoring functions. Treating the list as sufficient on its own would leave key program elements unaddressed. This entry is educational and not a substitute for legal advice tailored to your jurisdiction.
Does being placed on an insider list mean a person has done something wrong?
No. Inclusion on an insider list reflects access to specific inside information, not any allegation or finding of misconduct. The list is a factual record of who possesses or may possess material non-public information in connection with a particular matter, maintained so that access can be identified and, where relevant, restrictions applied. It is a control and documentation tool, not a disciplinary record or an indicator of wrongdoing.
Who should be responsible for maintaining and updating the insider list?
Responsibility is typically assigned to a designated function or individual, such as the compliance team, legal, or a company secretary role, depending on the organization's structure. The key implementation point is that ownership is clearly defined so that entries are added when access is granted and updated when circumstances change. Because obligations and expectations vary by jurisdiction and by the applicable framework, the specific allocation of responsibility should be confirmed with qualified counsel.
When should someone be added to or removed from the insider list?
As a general practice, a person is added when they gain access to the relevant inside information and updated or removed when that access ends or the information ceases to be inside information. Timely updating is intended to keep the record accurate as a reflection of who holds the information at any point. The precise triggers and timing expectations depend on the applicable rules and should be verified against primary sources and legal advice.
What information is typically recorded for each person on an insider list?
Entries generally identify the individual and the reason for and timing of their access to the specific inside information. The aim is to make clear who had access, to what, and when. Because the exact fields required can vary by jurisdiction and framework, organizations should confirm the specific data elements and retention expectations against primary regulatory sources rather than assume a universal format.
How does the insider list relate to other parts of the compliance program?
The insider list functions as a supporting record that other controls can draw upon, such as pre-clearance procedures, trading restrictions, training, and monitoring. It is intended to help identify who is subject to those controls in relation to a given matter, but it does not replace them. Its usefulness depends on accurate maintenance and integration with the broader program; on its own it does not restrict conduct or guarantee any legal outcome.

Common misconceptions

Maintaining an insider list by itself prevents insider dealing or market abuse.
An insider list is a record-keeping and accountability tool. It is intended to support the identification and control of persons with access to inside information, but it does not by itself prevent misconduct; effectiveness depends on accompanying controls, training, and monitoring.
Insider list obligations are the same everywhere, so one template satisfies all jurisdictions.
Insider list requirements are jurisdiction-specific and vary in the data fields, format, and retention periods mandated. Specific obligations, formats, and any deadlines should be confirmed against the applicable primary legal sources and, where necessary, with qualified legal counsel.
An insider list is an ethics measure reflecting company values.
An insider list is primarily a compliance and legal control that addresses adherence to securities and market abuse regulation with defined obligations. It sits on the compliance rather than the values-based ethics end of the spectrum, though ethical conduct around confidential information is a related concern.

Best practices

Maintain insider lists on a per-event or per-matter basis and record the date and time each person gains and loses access, so the record reflects the actual scope of exposure to inside information.
Confirm the required data fields, format, and retention period against the applicable primary regulatory sources for each relevant jurisdiction, since these requirements are jurisdiction-specific.
Notify each listed person of their inclusion and the associated legal and confidentiality obligations, and retain evidence of that acknowledgment.
Integrate insider list maintenance with broader program elements such as training, confidentiality controls, and monitoring rather than treating the list as a standalone safeguard.
Assign clear ownership for keeping lists accurate and current, and update entries promptly when access changes rather than reconstructing them after the fact.
Consult qualified legal counsel where obligations vary by local law or where deal-specific circumstances are ambiguous, treating internal guidance as educational and not a substitute for professional advice.